NewsCheck Point Claude Code Triple CVEs Hooks RCE MCP Bypass API ExfilCheck Point Research·high signalXBlueskyLinkedInCopy linkCVE-2025-59536 and CVE-2026-21852 enable RCE via Hooks, MCP consent bypass, and API key exfiltration by cloning malicious repos. All patched.SourceSource pageCheck Point Research↳ Follow the threadShared entity / Stack layerchrome-devtools-mcp 1.9.0 publishes itself as an Agent Plugins 1.0 package installable across five agent clientsGitHubShared entity / Stack layerCodenotch reads usage limits out of seven coding assistants' own local sessions and pins them to a macOS screen edgeGitHubShared entity / Stack layercc-connect bridges local coding agents to seven messaging platforms so you can drive them from your phoneGitHub TrendingShared entity / Stack layerPattern: agent session observability became a product category in about a weekGitHubShared entity / Stack layerTip: --worktree startup now checks out in parallel on git 2.32 and laterClaude Code ChangelogShared entity / Stack layerClaude Code MCP servers configured as `http` never connected if the server only spoke legacy HTTP+SSEGitHubShared entity / Stack layerVS Code 1.136 ships Agent Merge, and multi-root workspaces make you pick which folder's agent hooks loadVisual Studio CodeShared entity / Stack layerA dual-login proxy plugin lets GPT-6 Astra orchestrate Opus subagents inside Claude Coder/ClaudeAI (67 upvotes, 32 comments)