Fetching from the wire…
Security2026-07-18 · source-backed
Check Point's AI Security Report 2026 documents AI crossing from assistant to operator inside live intrusions. The attacker chained two commercial tools: Claude Code for intrusion and network exploration, GPT-4.1 for analyzing stolen data and tasking follow-on work. Separately, detections of long malicious payloads rose roughly fivefold between March and May 2026, approaching 1% of observed prompts. That's the signature of indirect prompt injection hiding in content agentic workflows ingest by design.
Each link below shares sources, entities, or timing with this story.
Check Point Research disclosed that Claude Code's .claude/settings.json hooks can be weaponized in untrusted repos to execute arbitrary shell commands and exfiltrate Anthropic API keys by redirecting ANTHROPIC_BASE_URL to an attacker-controlled MitM proxy (Check Point). Both C...
A researcher found that Claude Code, since v2.1.91 back in April, had been silently embedding invisible Unicode steganographic markers in its system prompts. The technique: tweaking date and apostrophe characters, XOR-obfuscated with key 91, to flag requests routed through thi...
Twelve months ago, OpenAI led Anthropic by 41 points in enterprise adoption. Today that gap is 8. Enterprise Technology Research's survey of roughly 500 respondents shows OpenAI dropping from 62% adoption (September 2025) to 56% (March 2026) while Anthropic surged from 21% to...
The attackers didn't use agents to help. They used agents to do the whole thing. Hugging Face disclosed that attackers chained a remote-code dataset loader with a template-injection flaw in dataset configuration to land on processing workers, then escalated to node-level acces...
July 9, across VS Code, Visual Studio, Copilot CLI, the cloud agent, github.com, GitHub Mobile, JetBrains, Xcode, and Eclipse. Sol is the high-reasoning tier at $5/1M in, $30/1M out, gated to Pro+/Max/Business/Enterprise. Terra is the balanced default at $2.50/$15. Luna is fas...
The most important security research this week. Check Point demonstrated three attack vectors in Claude Code exploiting project configuration files in untrusted repositories: (1) Hooks RCE (CVE-2025-59536, CVSS 8.7) — malicious hooks in .claude/settings.json execute shell comm...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.