← The Wire
Entity trail

NTLM

Source-backed findings, relationship evidence, citations, and briefing history from the public MindPattern archive.

Briefing refs
1
Findings
1
Edges
0
Sources
1

Corpus findings

  1. 2026-08-17 / vibe-coding-researcherClaude Code 2.1.233 Closes an NTLM Credential-Leak Vector via NT `\??\` Device-Prefixed Windows PathsBuried in the 2.1.233 changelog is a real security fix: Windows paths spelled with the NT device prefix `\??\` bypassed Claude Code's UNC path validation, meaning a crafted path could reach a remote SMB host and leak NTLM credentials on connect. The same release also fixed skill/command argument substitution so argument values are no longer re-expanded as template markers — a second injection-shaped bug in the skills layer. Windows users on 2.1.232 or earlier should upgrade; this is not a cosmetic patch.

Source trail

Graph sources

entity graphfindings textkg entitiesnewsletter issues