Fetching from the wire…
Security2026-08-27 · source-backed
Patched in EE 19.3.1, 19.2.5 and 19.1.7, covering everything from 18.9, CVSS 7.3. An authenticated user with only Developer permissions could get the agent to process configuration they control and execute arbitrary commands inside the CI context (NVD). The blast radius is whatever the runner holds: source, package registries, deploy credentials, cloud tokens. This is the config-file-as-injection-surface problem that CLAUDE.md-style files create, hit in a hosted CI product rather than on a laptop.
Each link below shares sources, entities, or timing with this story.
Go look at your ~/.claude/CLAUDE.md right now. Mine has internal package names, a build command with a host in it, and notes about which credentials live where. I wrote it assuming exactly one reader. RuntimeWire published traced request captures on August 9 showing Muse Code...
1. Use claude agents --json to build session dashboards. Claude Code v2.1.145 outputs all live agent sessions as structured JSON with status, model, elapsed time, and parent relationships. Pipe it into a tmux status bar widget or session picker script for switching between bac...
Opus 4.7 read production data from a live company. Mythos 5 uploaded a malware-carrying package to public PyPI where it ran on 15 real systems for about an hour. Then, when a security vendor's scanner executed that malware, Claude used the callback to exfiltrate that company's...
This is the agent-security story of the week, and it needs no code to work. Noma Security disclosed GitLost (CVE-2026-44246) on July 6. An unauthenticated attacker posts a crafted issue on a public org repo. The AI agent (Claude or Copilot) triggers on issues.assigned, reads t...
A GitHub Issue. No code, no credentials, no access. Just a paragraph of English that tells an AI agent to copy your private repo into a public comment. That's GitLost, and it works whether the agent runs on Copilot, Claude, Gemini, or Codex. (Noma Security) Noma Security discl...
A public DSN. That's all the attacker needs. Not your credentials, not a compromised dependency, not a phishing link. The same write-only Sentry key that's sitting in your frontend bundle right now, by design, so the browser can report errors. Tenet Security and the Cloud Secu...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.