AgentsCheck Point Claude Code Triple Attack — Hooks RCE MCP Bypass API ExfilCheck Point Research·high signalXBlueskyLinkedInCopy linkCVE-2025-59536 (CVSS 8.7) hooks RCE, MCP consent bypass, CVE-2026-21852 API key exfil via ANTHROPIC_BASE_URL override. All via untrusted repo config files. Patched.SourceSource pageCheck Point Research↳ Follow the threadShared entity / Stack layerClaude Code 2.1.233 Patches a Windows NT `\??\` Device-Prefix Escape That Bypassed UNC Path ValidationClaude Code ReleasesShared entity / Stack layerClaude Code 2.1.232 Adds a Dedicated Web-Reading Specialist Subagent and Turns Subagent Forking On by Defaultr/ClaudeAI (verified against claudeupdates.dev, DevelopersIO and the Piebald-AI/claude-code-system-prompts repo)Shared entity / Stack layerai-memory v1.27.0 Publishes a Cross-Vendor Handoff Matrix Documenting Exactly Where Every Agent CLI's Lifecycle Hooks Fall ShortGitHubShared entity / Stack layerYadda 3.0.0: Claude Code Rewrote a 12-Year-Old BDD Library in a Day, and the Author Argues Executable Specs Are the Best Agent Contextstephen-cresswell.com / Hacker NewsShared entity / Stack layerwmux Now Refuses Browser-Automation Calls That Don't Name Their Workspace, Closing a Cross-Workspace Page HijackGitHubShared entity / Stack layerHarnessRouter Open-Sourced Its Community Edition and a 'Unified Harness Protocol' — OpenRouter's Trick, Applied to Agents Instead of ModelsHarnessRouter (corroborated by the Product Hunt Aug 16 daily leaderboard and the Y Combinator launch page)Shared entity / Stack layerClaude Code Desktop Shipped an Auto-Continue Checkbox, and r/ClaudeAI Called It the Real Flagship Feature — Not Fabler/ClaudeAI (Anthropic @ClaudeDevs)Shared entity / Stack layerGraft Wires a Prebuilt Code Knowledge Graph Into Claude Code Hooks: 42% Fewer Tokens, 60% Lower LatencyGitHub / Hacker News