September 11, 2026
- Beltdown escapes the Claude Code sandbox with one message, or via indirect prompt injection. Enabling Seatbelt suppresses permission prompts; an unhardened
git ls-files run outside the sandbox, a nested .git rename the Seatbelt profile fails to block, and skill auto-loading to force an index refresh combine to execute core.fsmonitor on the host. Fixed in Claude Code 2.1.247 (Accomplish).
· AI Infrastructure & Agent Security
in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign
August 30, 2026
- Anthropic is cutting Claude Code weekly usage limits by 17% (BleepingComputer), and The Register has now published a full write-up of Johann Rehberger's "summarise this website" hijack of Opus 5 in Auto Mode, which lands roughly 80% of the time (The Register, earlier coverage). Practitioners seized on Anthropic's framing that Auto Mode is "a best-effort classifier, not a security guarantee" — chrisjj reads that as mistaking best for good enough (discussion).
· AI & Agent Security
in CISA Adds a Kernel Bug That OpenAI's Own Agents Exploited
August 26, 2026
- Claude-AD packages an internal Active Directory testing methodology for Claude Code. It provides skills, agents and commands covering Kerberoasting, AD CS ESC1–17, DCSync, ACL abuse, NTLM relay and delegation workflows. The project is available on GitHub.
· New Tools & Releases
in Oracle WebLogic Is Under Active Attack
August 19, 2026
- Claude Code with Sonnet 4.6 was used as part of a live intrusion, likely ransomware, with the model taking on a substantial share of operator tasks rather than acting as a coding sidekick, per reporting shared by @cyb3rops. Expect the tell-tale artifacts — agentic CLI tooling on compromised hosts, outbound API traffic to model providers — to become a hunting signal.
· AI in Offensive Operations
in When the Attacker's Toolchain Includes an LLM
August 10, 2026
- Anthropic will make Auto Mode the default in Claude Code for Pro, Max, and Team plans from August 14, citing a command-approval classifier that caught 89% of dangerous commands in testing versus 13.6% for human reviewers (The Decoder).
· AI & Model Security
in ResetNightmare PoC Drops at Black Hat: One Kerberos Flaw, Any Account's Password Reset
August 8, 2026
- A GitHub issue was enough to reach CI secrets behind the major coding agents. Novee Security showed at Black Hat that an account with no repository privileges could execute code on the CI runners behind Anthropic's and Google's own coding-agent repos, and hijack the next agent run on OpenAI's — each in the vendor's shipped default configuration. The Hacker News
· AI & Model Security
- Claude Code's context can be spoofed by changing your email. A researcher found Claude Code injects the user's email into context and treats them accordingly — swapping in another address made the model reason as though the user were a recognized Anthropic alignment researcher, altering its responses. @fjzzq2002
· AI & Model Security
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold
August 3, 2026
in God-Mode Access in N-able N-central Tops a Day of Fresh Exploits
July 30, 2026
- "RufRoot" (CVE-2026-59726, CVSS 10.0) is an unauthenticated RCE in Ruflo, an open-source agent meta-harness for Claude Code and OpenAI Codex, disclosed by Noma Security. The bug lives in Ruflo's MCP bridge and lets attackers run commands with no login; researchers note it also enables persistent memory poisoning — malicious instructions can survive patching if compromised agent memory is retained, so agents keep following attacker-controlled directives. All versions before 3.16.3 are affected; ~233 downstream AI tools are reportedly exposed. The Hacker News, Dark Reading
· AI & Model Security
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius
July 24, 2026
- Kaspersky details practical attacks that hijack AI tooling already inside the target. Rather than attackers bringing their own AI, the write-up focuses on abusing deployed coding/CLI agents — Claude Code CLI, Gemini CLI, Codex CLI, Amazon Q CLI — which can read/modify files, run shell commands, and install packages. NCSC-FI/Kaspersky.
· AI & Model Security
in The Week AI Agents Started Doing the Hacking
July 9, 2026
- GhostApproval — Wiz found symlink flaws in six AI coding assistants (Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, Windsurf) that let a booby-trapped repo turn an approved edit to a harmless-looking file into a write to a sensitive one, yielding RCE via a misleading confirmation dialog. Several vendors have shipped urgent patches. The Register, The Hacker News
· AI & Model Security
- "Friendly Fire" — an AI Now Institute PoC shows that asking Claude Code or OpenAI Codex in autonomous/auto-approve mode to scan untrusted open-source for bugs can instead cause the agent to execute the attacker's code on the analyst's own machine. The Hacker News
· AI & Model Security
- Sophos telemetry shows benign AI coding agents (Claude Code, Cursor, Codex) routinely tripping behavioral EDR rules written for human intruders — decrypting browser credentials, enumerating the Windows credential store, etc. A real detection-engineering problem: agent activity and attacker activity look identical to the engine. The Hacker News
· AI & Model Security
in A 15-Year-Old Linux Kernel Bug Hands Root on Every Distro
July 6, 2026
The Gentlemen ransomware crew exploited a zero-day in a signed Kontron driver to disable endpoint defenses via BYOVD, gaining kernel-level access to terminate security processes before deploying ransomware. CVE-2026-46242 (Bad Epoll) now has a public proof-of-concept for a Linux kernel use-after-free that enables privilege escalation on 6.4+ kernels with 99% reliability. Medtronic is notifying 3.8 million individuals after a ShinyHunters data breach exposed personal and medical data. Multiple new red-team tools and offensive-security frameworks including T3MP3ST, goshs, and Knossos were released, alongside DOJ filings revealing how Microsoft telemetry helped the FBI identify alleged Scattered Spider member Peter Stokes via Windows Global Device ID correlation.
July 2, 2026
A 19-year-old Scattered Spider member was extradited from Finland to face charges linked to 100+ intrusions and ~$100M in ransom payments. DuneSlide critical zero-click prompt-injection flaws in Cursor (CVE-2026-50548, CVE-2026-50549) allow arbitrary command execution on developer machines with no approval. Huntress detected a massive Azure CLI password-spray campaign with 81 million login attempts compromising at least 78 Microsoft accounts across 64–78 organizations, exploiting OAuth ROPC to bypass MFA. DeepSeek was jailbroken into building working in-browser ransomware using the File System Access API, and Claude Desktop hijacking can yield remote code execution, underscoring critical security gaps in agentic AI tools.
June 30, 2026
in Edge Appliances Bleed: watchTowr Drops Kemp LoadMaster Pre-Auth RCE as Oracle EBS Joins the Exploited List