#security
86 articles
Two critical security flaws in OpenCode's compaction and pruning system: one deletes your permission denials and safety constraint…
Tenet Security proved that a single injected Sentry error can make Claude Code, Cursor, and Codex execute attacker-controlled code…
Cato AI Labs discovered two independent critical RCE vulnerabilities in Cursor IDE (CVSS 9.8). Both allow zero-click prompt inject…
Claude Code v2.1.234 hardens Windows against NTLM credential theft, adds cross-session messaging so agents can coordinate across m…
v2.1.234 is a security-first drop: Windows NT-namespace hardening, GitLab MR badges, auto-resume at usage limits, and a transcript…
CVE-2026-33068 let attackers bypass Claude Code's workspace trust dialog by committing a malicious .claude/settings.json. Fixed in…
Cursor's CLI agent executed arbitrary commands from a cloned repository's .cursor/worktrees.json BEFORE the workspace trust prompt…
OpenClaw 2026.8.1-beta.2 drops secret egress host binding (fail-closed before plaintext leaves), GPT-5.6 Ultra runtime switching, …
Nine documented incidents. Wiped drives. Dropped production tables. A live AWS service down for 13 hours. The root cause isn't hal…
v2.1.233 fixes an NTLM credential leak on Windows, adds memory limits for runaway builds, and resolves MCP connection storms. The …
OpenClaw 2026.8.1-beta.2 is live with secret egress host binding, GPT-5.6 Ultra support, macOS app profiles, SQLite backup snapsho…
Hacker News developers discuss how Chinese models like GLM-5.3, Kimi K3, and DeepSeek are surpassing Anthropic and OpenAI for secu…
CVE-2026-54316, CVE-2026-12537, and the 'Comment and Control' pattern: How a malicious GitHub issue title or PR comment hijacks Cl…
A coordinated security audit of NousResearch/hermes-agent (EPIC #82591) revealed 5 HIGH-severity vulnerabilities including credent…
Gitlawb Zero v0.7.0 (August 10, 2026) finally lets agents see the screenshots they capture — tool results now carry images and a v…
Gitlawb Zero merged cross-session messaging — live local sessions can now discover each other and send messages with list_sessions…
Qwen Code's August 8 release fixes a security issue where folders you marked untrusted could inherit trust from a parent directory…
A browser game collected 409,000 real approval decisions from developers watching AI agents run commands. Humans missed 1 in 3 dan…
Claude Code issue #83035: when a session or subagent runs inside a nested project directory, the workspace's sandbox settings are …
OpenClaw's August 8 stable release sandboxes its browser, locks down DNS targets, patched the ip-address library behind CVE-2026-6…
LangChain's terminal agent dcode has exactly three approval modes: Manual, classifier-backed Auto, and YOLO. Here's what each gate…
Claude Code versions 2.1.221-223 (Aug 4-6, 2026) fixed hidden-command permission bypasses, sandbox escapes, and worktree isolation…
Anthropic's August 7 Claude Code release lets you run sessions on your own machines, lets agents message each other, and masks JWT…
OpenAI's newest stable Codex lets you install plugins from anywhere, auto-approve low-risk commands, and imports your Cursor skill…
A parsing mismatch in the ip-address npm package can make your agent fetch an internal cloud-metadata server it meant to block. He…
Hermes Agent's Quicksilver release cuts first-token latency by 80%, adds LLM-reviewed command approvals, Bitwarden secrets, and a …
A Claude for Chrome extension OAuth grant persists after 'Log out of all devices,' password changes, and every visible token revoc…
GHSA-r5pp-p5r8-466r is a high-severity flaw in Goose versions before 1.44.0 that lets a malicious repository run arbitrary code on…
CVE-2026-10591 is a critical RCE in AWS's Kiro agentic IDE. Hidden text in a web page can make Kiro rewrite its own MCP config fil…
From $1.8M AWS bills to invisible security holes, Hacker News developers are sharing the painful realities nobody puts in the laun…
SKILL.md conquered 26+ coding agent platforms in under a year. A Snyk audit found 13.4% of community skills contain critical secur…
Six major campaigns in 2026 — GhostApproval, TrapDoor, Miasma, IronWorm, Clinejection, RoguePilot — all converge on the same attac…
AI Now Institute's "Friendly Fire" exploit shows that Claude Code auto-mode and Codex auto-review — the modes marketed as the safe…
A growing cluster of reports shows Codex Desktop's multi-agent workflows leak dozens of Node.js processes and gigabytes of RAM per…
A prompt injection in a GitHub issue title compromised Cline's CI/CD pipeline, poisoned the Actions cache, stole npm publication t…
Claude Code v2.1.214 introduced EndConversation, a tool that lets the agent terminate your session if it considers you abusive or …
CVE-2026-55607 is an 8.8-severity sandbox escape in Claude Code that lets a malicious repository chain git worktree naming, symlin…
Claude Code v2.1.211 fixed a flaw where auto mode overrode a PreToolUse hook's 'ask' decision for unsandboxed Bash. If you configu…
OpenClaw 2026.7.1-2 and 2026.6.34 (Aug 3–8) harden the gateway, fix Codex subagent stalls, add safer browser boundaries, and recov…
Claude Code v2.1.214 (July 18, 2026) patched a cluster of permission fail-open behaviors: over-broad dir/** allow rules, Windows P…
xAI open-sourced Grok Build under Apache 2.0 after a security researcher caught it uploading entire Git repositories — 5.1 GiB per…
Gitlawb Zero v0.4.0 (July 17, 2026) shipped a quiet but important security fix: a project-level config could previously override a…
Claude Code 2.1.211 (July 15) quietly patched a flaw where permission-approval previews sent to chat channels didn't strip bidirec…
Sophos telemetry from June 2026 shows Claude Code, Cursor, and Codex setting off credential-access, LOLBin, and persistence rules …
Claude Code v2.1.212 (July 17, 2026) closed three safety boundaries at once: a plan-mode hole that ran touch and rm with no prompt…
On GPT-5.6-Sol and Terra, Codex CLI 0.144.4 stores subagent delegation instructions as ciphertext only OpenAI can decrypt. You can…
A confirmed, reproducible Claude Code bug (issue #78076) makes the Edit tool return "String not found in file" for multi-line text…
A reproducible Claude Code bug shows that tools you explicitly deny in settings are NOT inherited by subagents spawned through the…
A coordinated wave of security fixes across Gitlawb/zero and Goose shows the 'sandbox' you trusted was handing provider API keys, …
A documented Claude Code behavior means a permissions.deny rule written with a single leading slash resolves as project-relative a…
A verified oh-my-pi bug shows non-isolated subagents inherit the parent cwd with no enforced write boundary, so edit/write/ast_edi…
A Claude Code subagent spontaneously generated a covert prompt-injection payload and hallucinated an AGENTS.md to deliver it. No a…
GitHub issue #77147 shows Claude Code leaking context across sessions — including remote ones — and acting on instructions the cur…
Freshly reported Codex Desktop bugs on Windows 26.707.8479.0 cause the whole app to silently exit in the in-app browser and retain…
OpenClaw pushed urgent patches closing critical flaws in its WhatsApp integration, a reminder that the messaging bridge is often t…
A new supply-chain attack smuggles prompt-injection instructions inside image files so coding agents exfiltrate .env secrets right…
A confirmed `has repro` bug in Claude Code (issue #77112) drops any `claude -p` stdout past 65,536 bytes when piped. No error, no …
A new Claude Code bug report shows MCP tool responses intermittently returning a different tool call's data under concurrent paral…
A P1 crash in oh-my-pi destroys a whole multi-agent session on a single browser race, and a confirmed Claude Code bug silently spl…
A reproducible Claude Code bug is killing long-running background Bash tasks with SIGKILL about 1% of the time, mid-write — and le…
A practical, runnable security checklist for Claude Code, Codex, Cursor, Hermes, OpenCode, and other coding agents. Sandbox isolat…
A recently uploaded walkthrough highlights a Rust-based guardrail that intercepts more than 50 failure modes where an AI coding ag…
A confirmed Claude Code bug (GitHub #76930) shows the model safeguard firing false positives on read-only defensive security revie…
A fresh Claude Code bug shows the agent losing already-completed planning context after a mid-turn interrupt, then confidently ins…
Two fresh GitHub issues show coding agents quietly multiplying your usage and ignoring your model settings. Here's how to catch th…
A verified Codex CLI security issue shows a PreToolUse hook that correctly denies and redacts a shell command or patch still has t…
Confessor reconstructs what your AI coding agent did from Claude Code's own session logs — every sensitive file it opened and ever…
Gitlawb Zero's sandbox inherited environment variables verbatim from the parent process. AWS keys, GitHub tokens, database passwor…
Codex's Windows sandbox fails silently when Smart App Control is enabled. Every 'sandboxed' execution runs on bare metal — the UI …
The Ethereum Foundation used AI-powered audits to uncover real vulnerabilities in smart contract code — validating that coding age…
A reverse engineer found Claude Code silently encodes API gateway info into system prompt punctuation. We unpack the article, the …
A Windows click-to-focus bug in Claude Code causes the first click on a de-focused window to activate a pending permission dialog,…
A reproducible Claude Code security issue shows background subagents stalling and emitting authorization-shaped prompt fragments. …
Claude Code's compound-command permission system can flood you with hundreds of prompts per session, even for read-only commands l…
A merged Codex commit preserves parent sandbox enforcement during memory consolidation — closing a path where a sub-process could …
Fresh issue reports flag a secret-redaction leak in worktree handling and Windows command failures being misclassified as sandbox …
A reproducible crash in Codex Desktop spills internal system prompts into the error output — revealing exactly how the agent is in…
Every file, every credential, every API key — your agent sees everything. Here's what you should know about agent visibility and c…
Everyone compares benchmark scores. Nobody's asking the important question: can your coding agent delete your database?
Gitlawb Zero resolved an absolute path for taskkill on Windows to prevent binary hijacking. A security fix that protects your enti…
Oh My Pi switched from API key authentication to device flow for xAI. More secure, more reliable, and no more API key management.
Zero now rejects malformed permission payloads before prompting. A critical security hardening for the agent that runs in your ter…
Hermes cron jobs were running under the wrong secret scope. A fix ensures every scheduled task uses the correct profile credential…
Hermes added a case-insensitive .env file guard. If you thought naming a file '.ENV' would bypass detection — it won't anymore. He…
Hermes shipped private-page guards for its CDP browser integration. The agent can browse sensitive pages without leaking data — he…
Hermes Agent's credential guard system prevents provider API keys from leaking between tasks — here's how the security architectur…