Fetching from the wire…
Security2026-06-24 · source-backed
The June 24 release adds a sandbox.credentials setting that stops sandboxed commands from reading credential files and secret env vars, plus org-level model restrictions enforced through the picker, CLI flags, and env vars. Pair it with Anthropic's new Workload Identity Federation, which swaps static API keys for short-lived, scoped credentials issued per request via AWS IAM, GCP/Kubernetes service accounts, GitHub Actions, or Okta/OIDC (release notes). WIF kills the "static key to rotate or leak" problem outright. Both ship as direct hardening against the credential-exfiltration class hitting agentic tools. This is what a vendor responding to real attacks looks like.
Each link below shares sources, entities, or timing with this story.
Three companies shipped standalone agent platforms in the same week, and none of them are IDE plugins. Google launched Antigravity 2.0 at I/O with a desktop app, a Go-based CLI, and an SDK for self-hosted agent deployments. No IDE. It's conversations, projects, and multi-agent...
Anthropic introduced enterprise-managed MCP connector access starting with Okta, letting admins provision a connector once so users get zero-touch access on first login, with centralized authorization across Claude chat, Claude Code, and Cowork on Team and Enterprise plans. Th...
A single PR title. A hidden HTML comment in an issue body. No jailbreak, no social engineering, no user interaction required. Your credentials get exfiltrated through GitHub's own infrastructure before you ever see the notification. Security researcher Aonan Guan (Wyze Labs) a...
The release notes add a user-facing "effort control" selector to choose how deeply Claude thinks per response, self-hosted sandboxes for Claude Managed Agents as an alternative to running tool execution on Anthropic infra, and Cowork support for the Analytics API plus OpenTele...
The supply chain verification system you trust just got bypassed by a worm that carries valid provenance attestations. On May 11, an attacker group called TeamPCP launched Mini Shai-Hulud, compromising 172 npm and PyPI packages across 403 malicious versions totaling 518 millio...
Lasso Security published research demonstrating that Claude Code's --dangerously-skip-permissions flag enables indirect prompt injection via poisoned READMEs, documentation files, and MCP responses. Then they did something unusual: they released the defense alongside the attac...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.