Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Plugin4Shell Supply-Chain Flaw in Claude Code, Codex, and Copilot: Detection and Remediation Guide
Introduction Air Security disclosed a supply-chain vulnerability class this week that should be on every CISO's radar — especially organizat...
Self-Generated Prompt Injections in AI Compaction Summaries: Defending Claude Code and Coding Agents Against Persistence Attacks
A New Persistence Layer: When the AI Writes Its Own Malware Instructions Simon Willison's September 2026 write-up on self-generated prompt i...
Malicious .git Configs Hijack Claude Code, Codex, Cursor AI Agents — Detection and Hardening Guide
Introduction Manifold Security has disclosed a cluster of eight vulnerabilities spanning seven command-line AI coding agents — including Ant...
Securing Claude Code: Detection, Compliance API Monitoring, and Identity Governance for AI Coding Agents
Introduction AI coding assistants have crossed a line that security teams can no longer ignore. Claude Code is not a chatbot in a browser ta...
Anthropic Cuts Claude Code Weekly Limits by 17%: What Security and Platform Teams Need to Do Now
Introduction Anthropic has announced a permanent change to Claude Code's standard weekly usage limits — a 25% increase to the baseline limit...
Claude Code Opus 5 Auto Mode Prompt Injection Bypass: Detection and Hardening Guide for AI Coding Agents
Overview Johann Rehberger — one of the most credible prompt injection researchers working today — has demonstrated a bypass of Anthropic's C...
Prompt Injection Hijacks Claude Code Opus 5 Auto Mode — Detection and Hardening Guide
Researchers have demonstrated that a simple webpage summarization request can hijack Claude Code running Opus 5 in Auto Mode — the now-defau...
Claude Code Auto Mode Now Default: Defending Against Prompt Injection and Unsupervised Agent Execution
Introduction Anthropic has made Auto mode the default behavior in Claude Code for Pro, Max, and Team plan subscribers, as covered in Simon W...
Claude Code & Gemini CLI Prompt-Injection Attack: GitHub Issue Reaches CI Workflow Secrets — Detection and Remediation Guide
A GitHub Issue Just Became an RCE Primitive Against Vendor CI/CD Security researchers at Novee Security demonstrated — against Anthropic's C...