Fetching from the wire…
Security2026-07-18 · source-backed
The GitLab advisory covers out-of-band data exfiltration from Claude Code via a domain sitting on the static WebFetch allowlist. The generalizable lesson is the one to keep: any allowlisted domain that lets third parties host arbitrary content is a legal exfil channel. Audit your allowlists by asking "can an attacker put a file here?" not "is this vendor reputable?" HuggingFace is extremely reputable. It also lets anyone upload a file.
Each link below shares sources, entities, or timing with this story.
Terra Security's adversarial testing found recurring vulnerability patterns across AI coding tools including Claude Code, Loveable, and Base44. CVE-2026-25724 is a path traversal vulnerability in Claude Code (pre-2.1.7) where symbolic links bypass deny rules in settings.json b...
Go look at your ~/.claude/CLAUDE.md right now. Mine has internal package names, a build command with a host in it, and notes about which credentials live where. I wrote it assuming exactly one reader. RuntimeWire published traced request captures on August 9 showing Muse Code...
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
Check Point Research disclosed CVE-2025-59536 and CVE-2026-21852 — two vulnerabilities that weaponize Claude Code's project configuration system against its users. This matters because an Agents Anonymous survey this week showed 90% of practitioners at their SF meetup use Clau...
--restricted or CLAUDE_CODE_RESTRICTED=1 removes the built-in tools that run commands or code plus WebFetch unless explicitly named in --tools, confines file tools to the working directory, refuses bypassPermissions, and ignores user, project and local settings files entirely...
Go rotate a key. I'll wait. Claude Code 2.1.246, released August 25, lists this in its changelog: a fix for "telemetry and metrics requests to Anthropic carrying the API key configured for a third-party gateway (ANTHROPIC_BASE_URL); a credential is now only sent to its own hos...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.