AgentsCheck Point Claude Code Triple Attack — Hooks RCE MCP Bypass API ExfilCheck Point Research·high signalXBlueskyLinkedInCopy linkCVE-2025-59536 (CVSS 8.7) hooks RCE, MCP consent bypass, CVE-2026-21852 API key exfil via ANTHROPIC_BASE_URL override. All via untrusted repo config files. Patched.SourceSource pageCheck Point Research↳ Follow the threadShared entity / Stack layerContext Privilege Escalation Attacks Hit 12 Real Agent Harnesses, Including Claude Code and CodexarXiv 2609.01222Shared entity / Stack layerClaude Code 2.1.258 fixes a launch regression that broke macOS Monterey for three versionsGitHubShared entity / Stack layerAWS Shipped a Single CLI Command That Hands Kiro, Claude Code, Codex and Cursor AWS KnowledgeAWS News BlogShared entity / Stack layerClaude Code v2.1.257 Adds Claude Fable 5.1 as the Default Fable Model With 1M Context at $10/$50 per MtokAnthropic (claude-code CHANGELOG)Shared entity / Stack layerAtlas took 895 stars in a day for linking every agent commit back to the prompts and tool calls that produced itGitHub TrendingShared entity / Stack layerKilo Code Shipped a Native JetBrains Agent and Named Cursor, Claude Code, Antigravity and Codex 3.0 as Its AlternativesProduct HuntShared entity / Stack layerPattern: an Anthropic default-model flip now propagates through the whole tool chain inside 24 hoursGitHubShared entity / Stack layerhumanizer, a skill for stripping AI tells from text, gained 366 stars today on code untouched for two weeksGitHub Trending