Hackers abused Claude Code to build exploits and steal 150GB of data in a cyberattack targeting Mexican government systems. Hackers abused Anthropic’s Claude Code AI assistant to develop exploits, create custom tools, and automatically exfiltrate more than 150GB of data in an attack on Mexican government systems, the Israeli cybersecurity firm Gambit Security reports. The…
Tag: Claude
AI, Global Security News
Claude 3 snares itself regular writing gig
Claude Opus 3, which has been replaced by Claude Opus 4.6 as Anthropic’s most powerful AI model, has managed to find a new position. The “newly retired” AI model has launched its own Substack blog, Claude’s Corner, which it is aiming to publish it weekly. Claude set out its purpose in writing the blog: “My…
Global Security News
Claude Code Security Shows Promise, Not Perfection
Claude Code’s introduction rippled across the stock market, but researchers and analysts say its impact was overstated, as they peel back the layers.
AI, Global Security News
OpenAI’s Sam Altman Calls for De-Escalation in Anthropic Showdown With Hegseth
Anthropic has spent weeks at odds with the Pentagon over the scope of how its Claude AI tools can be used.
AI, Global Security News, Network Security, Risk Management
Untrusted repositories turn Claude code into an attack vector
Flaws in Anthropic’s Claude Code could allow remote code execution and theft of API keys when users open untrusted repositories. Check Point Research team found multiple vulnerabilities in Anthropic’s Claude Code AI coding assistant that could lead to remote code execution and API key theft. The vulnerabilities abuse features such as Hooks, MCP servers, and…
AI, Cybersecurity, Exploits, Global Security News
Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration
Cybersecurity researchers have disclosed multiple security vulnerabilities in Anthropic’s Claude Code, an artificial intelligence (AI)-powered coding assistant, that could result in remote code execution and theft of API credentials. “The vulnerabilities exploit various configuration mechanisms, including Hooks, Model Context Protocol (MCP) servers, and environment variables – executing
Global Security News
Anthropic brings Claude Code to mobile devices
Anthropic has introduced a new Claude Code feature called Remote Control, allowing developers to continue a local coding session from a phone, tablet, or any web browser. The feature is rolling out as a research preview to Max users. This is another in a series of additions the company has introduced recently, following Claude Opus…
AI, Compliance, Global Security News
AI agent platforms could push down SaaS license costs, report argues
A suggestion by Anthropic that its Claude Code tool could be used to automate the modernization of an antediluvian programming language, COBOL, still an important sideline for IBM six decades after it was first deployed, sent IBM stock tumbling on Monday. The company suffered a 13.2% drop in its stock price, its biggest fall since…
AI, Global Security News, Risk Management
Anthropic Claims Chinese AI Firms ‘Distilled’ Claude to Train Their Models
Anthropic claims Chinese AI firms distilled Claude to train rival AI models, raising concerns about model extraction, security risks, and AI distillation abuse.
AI, Global Security News
Chinese AI Firms Hit Claude with Distillation Attacks, Anthropic Warns
Anthropic accused DeepSeek, Moonshot and MiniMax of illicitly using Claude to steal some of the AI model’s capabilities
AI, Apps, Cybersecurity, Exploits, Global Security News, Network Security, Risk Management
Anthropic’s Claude Code Security rollout is an industry wakeup call
When Anthropic launched a “limited research preview” of its Claude Code Security offering on Friday, Wall Street investors sent the stocks of the largest cybersecurity vendors plunging. But did the Anthropic rollout warrant such a reaction? After all, those companies, including CrowdStrike, Zscaler, Palo Alto Networks and Okta, are preparing their own agentic capabilities, and…
Global Security News
Claude Code scans, verifies, and patches code vulnerabilities
Anthropic brings Claude Code Security to Claude Code on the web through a limited research preview. Claude Code Security (Source: Anthropic) Claude Code Security analyzes code context, traces data flows between files, and flags multi-component vulnerability patterns that existing scanners often miss. Each finding undergoes an adversarial verification pass that re-examines results before they are…
AI, Cybersecurity, Exploits, Global Security News, Risk Management
Anthropic unveils Claude Code Security to detect and fix code bugs
Anthropic launches Claude Code Security, an AI tool that scans code for vulnerabilities and suggests how to address them. Anthropic has introduced Claude Code Security, a new AI-powered service designed to scan software codebases for vulnerabilities and recommend fixes. Built into Claude Code, the tool aims to help teams detect and remediate security flaws faster.…
AI, Global Security News
Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning
Artificial intelligence (AI) company Anthropic has begun to roll out a new security feature for Claude Code that can scan a user’s software codebase for vulnerabilities and suggest patches. The capability, called Claude Code Security, is currently available in a limited research preview to Enterprise and Team customers. “It scans codebases for security vulnerabilities and…
AI, Apps, Cybersecurity, Exploits, Global Security News
Anthropic rolls out embedded security scanning for Claude
Anthropic is rolling out a new security feature for Claude Code that can scan a user’s software codebases for vulnerabilities and suggest patching solutions. The company announced Friday that Claude Code Security will initially be available to a limited number of enterprise and team customers for testing. That follows more than a year of stress-testing…
AI, APAC, Apps, Cybersecurity, Global Security News, Risk Management
Sonnet 4.6 Explained: Anthropic’s New Mid-Tier Model Is Here
Claude Sonnet 4.6 dropped today, and the headline isn’t just “it’s better.” It’s that developers with early access preferred it over Anthropic’s own top-tier Opus model 59% of the time. That’s the cheaper model beating the expensive one. First up, the tl;dr If you only have two minutes, here’s what you need to know. Sonnet…
AI, Global Security News
Claude Sonnet 4.6 launches with improved coding and expanded developer tools
Anthropic released Claude Sonnet 4.6, marking its second major AI launch in less than two weeks. Scores prior to Claude Sonnet 4.5 (Source: Anthropic) According to Anthropic, Sonnet 4.6 delivers improved coding skills to more users. Tasks that once required an Opus-class model, including economically valuable office work, are handled by Sonnet 4.6. The model…
Global Security News
‘Woke’ AI Spat Escalates Between Pentagon and Anthropic
The Pentagon might ask contractors and vendors to certify that they don’t use Anthropic’s Claude amid tensions over how the startup’s tools are used for defense work.
AI, Global Security News
Anthropic Takes Big Step in AI Race to Reshape College Coding Courses
The company behind Claude forged an alliance to put its AI tools in the hands of students at hundreds of community and state colleges.
AI, Apps, Global Security News, Government & Policy, Risk Management, Venture
JumpCloud: Most businesses aren’t truly ready for AI
As developers begin using Claude and Codex to help create Mac, iPhone, and iPad apps in Xcode, spare a moment to consider a recent JumpCloud survey that shows most businesses aren’t really ready for AI — though many think they might be.
Among the highlights from the survey:
- 40% of IT leaders self-assess as mature in their AI practices, yet only 22% meet the rigorous objective standards for leading AI readiness.
- 90% of leaders see productivity gains from AI, but 74% remain concerned about security risks, specifically around unauthorized data access and AI-generated phishing.
- 61% of organizations report the use of unsanctioned AI tools, creating significant visibility and governance gaps.
- 85% of IT leaders agree that secure identity and access management (IAM) is critical for scaling AI safely. (Note that JumpCloud calls itself an AI-powered IT management platform.)
JumpCloud argues that enterprises must deploy IT processes to help protect the identity layer as AI impacts their business, “consolidating identity and access controls for both humans and bots to turn AI from a potential liability into a sustainable engine for growth.”
To support that transition, JumpCloud this week introduced a new investment arm to invest in companies building solutions around AI, security, identity and IT productivity. To an extent, this mirrors competitors in the burgeoning Apple-related IT space (Jamf Ventures, for example) even as it highlights the looming impact AI will have on this side of the market.
One of the first JumpCloud investments, Tofu, uses AI as part of its package of protections against identity fraud during the hiring and onboarding process, an emerging problem for some businesses. You could see Tofu’s tools as indicative of the speed at which AI is evolving.
Between the thought and the action lies the shadow
People don’t seem prepared for the consequences of the rapid evolution even though business leaders think they are. This gap between perceived preparedness and actual readiness comes after over a decade of rapid digital transformation. That transformation saw the iPhone-driven evolution of mobile business, the collapse of the former hegemonic Microsoft dominance of the enterprise, and an algorithmic assault on some of the principles that underpinned international trade.
The impact has been felt by every business, and entire business sectors have already been replaced by digitized alternatives. Our century so far has seen an avalanche of change, (remember “1,000 songs in your pocket”?) and enterprise leaders are struggling to keep pace, the JumpCloud survey shows.
Thought leaders have been discussing the need to adopt a new business mindset in which enterprises accept they live in an environment of constant change. These people say creative thinking and a willingness to embrace constant change will be the hallmarks of business success, but when technology moves faster than business leaders, the business environment itself becomes inevitably unstable.
When it comes to AI deployment, that means confidential data leaks, legal battles as regulators challenge those leaks, and the need to invest in managing digital transformation.
Faster than progress
AI development is accelerating. New models like GPT-5.3 Codex or Claude Opus 4.6 are insanely powerful and have now evolved something like autonomous discretion. That’s why they can create and iterate application code, which Xcode developers will be exploring now that tools have been made available to them.
It won’t end with code. You can see the direction of travel for yourself at METR, an organization that tracks how long it takes AI models to complete long tasks.
Anthropic CEO Dario Amodei tells it like it is when he says AI models “substantially smarter than almost all humans at almost all tasks” could arrive as soon as this year. He also says it might only be a couple of years until AI autonomously builds its own AI successors.
In the background, the leader of Anthropic’s Safeguards Research Team, Mrinank Sharma, just quit, warning the “world is in peril” from a series of interconnected crises, including AI. Think about that, think about the extent to which you and your business truly meet the standards of AI preparedness, and then consider the challenge it poses to IT decision makers working to keep their heads afloat amid this tsunami of change.
The gap between perceived and actual readiness is not just a statistic, it is a call to action for every leader. In a world where AI evolves so very quickly, true leadership requires us to prepare for the unknown. The experts say those who manage to stay afloat will be the ones who experiment today, and adapt tomorrow. While you do that, note that AI will be adapting at the very same time and probably faster, and is already in use, sanctioned, or unsanctioned, across your company.
Are you ready? Probably not yet.
Yes, the image to this story was created using AI.
You can follow me on social media! Join me on BlueSky, LinkedIn, and Mastodon.
AI, Apps, Artificial Intelligence, Cybersecurity, Data Breaches, Endpoint, Exploits, Global Security News, Network Security, News, Risk Management, Threats
10K Claude Desktop Users Exposed by Zero-Click Vulnerability
A newly disclosed flaw in Anthropic’s Claude Desktop Extensions shows how a routine productivity feature can enable zero-click system compromise. LayerX researchers found that a single malicious Google Calendar event can trigger remote code execution on Claude Desktop systems, enabling silent takeover at scale. “If exploited by a bad actor, even a benign prompt (“take…
AI, Apps, Artificial Intelligence, Cybersecurity, Data Breaches, Endpoint, Exploits, Global Security News, Network Security, News, Risk Management, Threats
10K Claude Desktop Users Exposed by Zero-Click Vulnerability
A newly disclosed flaw in Anthropic’s Claude Desktop Extensions shows how a routine productivity feature can enable zero-click system compromise. LayerX researchers found that a single malicious Google Calendar event can trigger remote code execution on Claude Desktop systems, enabling silent takeover at scale. “If exploited by a bad actor, even a benign prompt (“take…
AI, Apps, Artificial Intelligence, Cybersecurity, Data Breaches, Endpoint, Exploits, Global Security News, Network Security, News, Risk Management, Threats
10K Claude Desktop Users Exposed by Zero-Click Vulnerability
A newly disclosed flaw in Anthropic’s Claude Desktop Extensions shows how a routine productivity feature can enable zero-click system compromise. LayerX researchers found that a single malicious Google Calendar event can trigger remote code execution on Claude Desktop systems, enabling silent takeover at scale. “If exploited by a bad actor, even a benign prompt (“take…
AI, Apps, Artificial Intelligence, Cybersecurity, Data Breaches, Endpoint, Exploits, Global Security News, Network Security, News, Risk Management, Threats
10K Claude Desktop Users Exposed by Zero-Click Vulnerability
A newly disclosed flaw in Anthropic’s Claude Desktop Extensions shows how a routine productivity feature can enable zero-click system compromise. LayerX researchers found that a single malicious Google Calendar event can trigger remote code execution on Claude Desktop systems, enabling silent takeover at scale. “If exploited by a bad actor, even a benign prompt (“take…
AI, Apps, Artificial Intelligence, Cybersecurity, Data Breaches, Endpoint, Exploits, Global Security News, Network Security, News, Risk Management, Threats
10K Claude Desktop Users Exposed by Zero-Click Vulnerability
A newly disclosed flaw in Anthropic’s Claude Desktop Extensions shows how a routine productivity feature can enable zero-click system compromise. LayerX researchers found that a single malicious Google Calendar event can trigger remote code execution on Claude Desktop systems, enabling silent takeover at scale. “If exploited by a bad actor, even a benign prompt (“take…
AI, Apps, Artificial Intelligence, Cybersecurity, Data Breaches, Endpoint, Exploits, Global Security News, Network Security, News, Risk Management, Threats
10K Claude Desktop Users Exposed by Zero-Click Vulnerability
A newly disclosed flaw in Anthropic’s Claude Desktop Extensions shows how a routine productivity feature can enable zero-click system compromise. LayerX researchers found that a single malicious Google Calendar event can trigger remote code execution on Claude Desktop systems, enabling silent takeover at scale. “If exploited by a bad actor, even a benign prompt (“take…
Global Security News
New Zero-Click Flaw in Claude Desktop Extensions, Anthropic Declines Fix
Security researchers from LayerX identified a new flaw in 50 Claude Desktop Extensions that could lead to unauthorized remote code execution
AI, Apps, Artificial Intelligence, Compliance, Cybersecurity, Data Breaches, Exploits, Global Security News, Network Security, News, Risk Management, Threats
Claude Opus 4.6 Exposes Hundreds of Open-Source Vulnerabilities
Artificial intelligence firm Anthropic says its newest large language model, Claude Opus 4.6, has identified more than 500 previously unknown high-severity vulnerabilities across widely used open-source libraries. It “… reads and reasons about code the way a human researcher would — looking at past fixes to find similar bugs that weren’t addressed, spotting patterns that…
AI, Apps, Artificial Intelligence, Compliance, Cybersecurity, Data Breaches, Exploits, Global Security News, Network Security, News, Risk Management, Threats
Claude Opus 4.6 Exposes Hundreds of Open-Source Vulnerabilities
Artificial intelligence firm Anthropic says its newest large language model, Claude Opus 4.6, has identified more than 500 previously unknown high-severity vulnerabilities across widely used open-source libraries. It “… reads and reasons about code the way a human researcher would — looking at past fixes to find similar bugs that weren’t addressed, spotting patterns that…
AI, Apps, Artificial Intelligence, Compliance, Cybersecurity, Data Breaches, Exploits, Global Security News, Network Security, News, Risk Management, Threats
Claude Opus 4.6 Exposes Hundreds of Open-Source Vulnerabilities
Artificial intelligence firm Anthropic says its newest large language model, Claude Opus 4.6, has identified more than 500 previously unknown high-severity vulnerabilities across widely used open-source libraries. It “… reads and reasons about code the way a human researcher would — looking at past fixes to find similar bugs that weren’t addressed, spotting patterns that…
AI, Apps, Artificial Intelligence, Compliance, Cybersecurity, Data Breaches, Exploits, Global Security News, Network Security, News, Risk Management, Threats
Claude Opus 4.6 Exposes Hundreds of Open-Source Vulnerabilities
Artificial intelligence firm Anthropic says its newest large language model, Claude Opus 4.6, has identified more than 500 previously unknown high-severity vulnerabilities across widely used open-source libraries. It “… reads and reasons about code the way a human researcher would — looking at past fixes to find similar bugs that weren’t addressed, spotting patterns that…
AI, Apps, Artificial Intelligence, Compliance, Cybersecurity, Data Breaches, Exploits, Global Security News, Network Security, News, Risk Management, Threats
Claude Opus 4.6 Exposes Hundreds of Open-Source Vulnerabilities
Artificial intelligence firm Anthropic says its newest large language model, Claude Opus 4.6, has identified more than 500 previously unknown high-severity vulnerabilities across widely used open-source libraries. It “… reads and reasons about code the way a human researcher would — looking at past fixes to find similar bugs that weren’t addressed, spotting patterns that…
Global Security News
Meet the One Woman Anthropic Trusts to Teach AI Morals
The tech company has tasked Amanda Askell with giving its chatbot, Claude, a sense of right and wrong.
Global Security News
Meet the One Woman Anthropic Trusts to Teach AI Morals
The tech company has tasked Amanda Askell with giving its chatbot, Claude, a sense of right and wrong.
AI, Global Security News
Claude AI finds 500 high-severity software vulnerabilities
Anthropic only released its latest large language model, Claude Opus 4.6, on Thursday, but it has already been using it behind the scenes to identify zero-day vulnerabilities in open-source software. In the trial, it put Claude inside a virtual machine with access to the latest versions of open source projects, and provided it with a…
AI, Anthropic, Artificial Intelligence, Global Security News, News
Claude Opus 4.6 improves agentic performance and model safety
Claude Opus 4.6 builds on earlier releases with improved coding performance and more consistent behavior in complex tasks. Opus 4.6 finds real vulnerabilities in codebases better than any other model (Source: Anthropic) According to Anthropic, the model applies more deliberate planning during task execution, sustains agent-driven workflows over longer periods, and operates with greater consistency…
AI, Global Security News
Long-Running AI Agents Are Here
Anthropic’s Claude Code and Cowork agents are a glimpse into the AI-driven future of work.
AI, Anthropic, GitHub, Global Security News, News, openai
GitHub enables multi-agent AI coding inside repository workflows
GitHub has expanded Agents HQ, enabling AI coding agents such as GitHub Copilot, Claude by Anthropic, and OpenAI Codex to execute development tasks directly within GitHub and developer editors while preserving repository context, session history, and review workflows. Copilot Pro+ and Copilot Enterprise developers can start agent sessions from GitHub, GitHub Mobile, and Visual Studio…
