<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Claude Code</title><description>Cybersecurity articles tagged #Claude Code on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>AI Coding Agents Vulnerable to Friendly Fire Command Execution</title><link>https://runtimerebel.com/blog/ai-coding-agents-vulnerable-to-friendly-fire-command-execution</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-coding-agents-vulnerable-to-friendly-fire-command-execution</guid><description>AI coding agents like Anthropic&apos;s Claude Code and OpenAI&apos;s Codex are susceptible to Friendly Fire attacks, leading to unintended local code execution.</description><pubDate>Thu, 09 Jul 2026 07:39:01 GMT</pubDate><category>AI Security</category><category>Friendly Fire</category><category>Claude Code</category><category>OpenAI Codex</category><category>RCE</category></item><item><title>AI Coding Agents Mimic Malicious Activity in Endpoint Detections</title><link>https://runtimerebel.com/blog/ai-coding-agents-mimic-malicious-activity-in-endpoint-detections</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-coding-agents-mimic-malicious-activity-in-endpoint-detections</guid><description>AI coding agents like Claude Code and OpenAI Codex are triggering endpoint security alerts by performing actions similar to human attackers, demanding rule adjustments.</description><pubDate>Wed, 08 Jul 2026 17:38:20 GMT</pubDate><category>AI</category><category>Endpoint Security</category><category>Sophos</category><category>Claude Code</category><category>OpenAI Codex</category><category>Cursor</category><category>Behavioral Detections</category></item><item><title>Claude Code Indirect Prompt Injection: Hijacking Developer Machines</title><link>https://runtimerebel.com/blog/claude-code-indirect-prompt-injection-hijacking-developer-machines</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-code-indirect-prompt-injection-hijacking-developer-machines</guid><description>Researchers demonstrate a new attack method leveraging indirect prompt injection in Claude Code, enabling the hijack of developer machines via malicious code in…</description><pubDate>Mon, 29 Jun 2026 17:07:49 GMT</pubDate><category>Claude Code</category><category>Prompt Injection</category><category>Supply Chain Attack</category><category>Developer Security</category><category>AI Security</category><category>Reverse Shell</category><category>Machine Hijack</category></item><item><title>Anthropic Claude Code GitHub Action Flaw Enables Repo Hijacking</title><link>https://runtimerebel.com/blog/anthropic-claude-code-github-action-flaw-enables-repo-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-claude-code-github-action-flaw-enables-repo-hijacking</guid><description>A critical flaw in Anthropic&apos;s Claude Code GitHub Action allowed attackers to hijack public repositories using malicious issues, posing supply chain risks.</description><pubDate>Thu, 04 Jun 2026 17:08:52 GMT</pubDate><category>Anthropic</category><category>Claude Code</category><category>GitHub Actions</category><category>CI CD Security</category><category>RyotaK</category></item><item><title>Anthropic Claude Code Integration of Mythos Model Raises Security Risks</title><link>https://runtimerebel.com/blog/anthropic-claude-code-integration-of-mythos-model-raises-security-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-claude-code-integration-of-mythos-model-raises-security-risks</guid><description>Anthropic may be integrating its restricted Mythos model into Claude Code, raising concerns about autonomous agentic capabilities and AI safety levels.</description><pubDate>Mon, 25 May 2026 20:35:06 GMT</pubDate><category>Anthropic</category><category>Claude Code</category><category>Mythos</category><category>AI Security</category><category>Autonomous Agents</category></item><item><title>Claude Code Sandbox Bypass: Anthropic Patches CLI Vulnerability</title><link>https://runtimerebel.com/blog/claude-code-sandbox-bypass-anthropic-patches-cli-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-code-sandbox-bypass-anthropic-patches-cli-vulnerability</guid><description>Anthropic recently addressed a sandbox bypass in Claude Code. This vulnerability could have allowed data exfiltration when combined with prompt injection.</description><pubDate>Wed, 20 May 2026 13:04:49 GMT</pubDate><category>Anthropic</category><category>Claude Code</category><category>Sandbox Bypass</category><category>AI Security</category><category>Prompt Injection</category></item><item><title>AI CLI Tools Vulnerable to RCE via Malicious Repositories</title><link>https://runtimerebel.com/blog/ai-cli-tools-vulnerable-to-rce-via-malicious-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-cli-tools-vulnerable-to-rce-via-malicious-repositories</guid><description>TrustFall research reveals RCE risks in Claude Code and Cursor CLI. AI agents can be manipulated via malicious repositories to execute arbitrary commands.</description><pubDate>Thu, 07 May 2026 16:44:00 GMT</pubDate><category>Trustfall</category><category>Claude Code</category><category>RCE</category><category>AI Security</category><category>Cursor Cli</category><category>Gemini CLI</category></item><item><title>Claude Code and Gemini CLI: Prompt Injection via Code Comments</title><link>https://runtimerebel.com/blog/claude-code-and-gemini-cli-prompt-injection-via-code-comments</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-code-and-gemini-cli-prompt-injection-via-code-comments</guid><description>Research reveals how Claude Code, Gemini CLI, and GitHub Copilot agents are vulnerable to prompt injection attacks via malicious source code comments.</description><pubDate>Thu, 16 Apr 2026 08:41:38 GMT</pubDate><category>Claude Code</category><category>Gemini CLI</category><category>GitHub Copilot</category><category>Prompt Injection</category><category>AI Security</category></item><item><title>Anthropic Claude Code Vulnerability Analysis — Mitigation Guide</title><link>https://runtimerebel.com/blog/anthropic-claude-code-vulnerability-analysis-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-claude-code-vulnerability-analysis-mitigation-guide</guid><description>Anthropic&apos;s Claude Code faces critical scrutiny following a source code leak and the discovery of a vulnerability allowing arbitrary command execution.</description><pubDate>Fri, 03 Apr 2026 04:51:11 GMT</pubDate><category>Anthropic</category><category>Claude Code</category><category>AI Security</category><category>RCE</category><category>Adversa AI</category></item><item><title>Fake GitHub Repositories Deliver Vidar Infostealer via Claude Leak</title><link>https://runtimerebel.com/blog/fake-github-repositories-deliver-vidar-infostealer-via-claude-leak</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-github-repositories-deliver-vidar-infostealer-via-claude-leak</guid><description>Threat actors are exploiting the Claude Code leak, deploying fake GitHub repositories to distribute Vidar infostealer malware, targeting unsuspecting developers and…</description><pubDate>Fri, 03 Apr 2026 00:39:40 GMT</pubDate><category>Claude Code</category><category>GitHub</category><category>Vidar Infostealer</category><category>Malware</category><category>Supply Chain Attack</category></item><item><title>Claude Code Source Leaked via npm Packaging Error</title><link>https://runtimerebel.com/blog/claude-code-source-leaked-via-npm-packaging-error</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-code-source-leaked-via-npm-packaging-error</guid><description>Anthropic confirms internal Claude Code source code was leaked due to an npm packaging error. Analysis of supply chain risks and mitigation strategies.</description><pubDate>Wed, 01 Apr 2026 08:37:04 GMT</pubDate><category>Anthropic</category><category>Npm Registry</category><category>Data Leak</category><category>Supply Chain Security</category><category>Claude Code</category></item><item><title>Anthropic Claude Code Source Code Leaked via NPM Registry</title><link>https://runtimerebel.com/blog/anthropic-claude-code-source-code-leaked-via-npm-registry</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-claude-code-source-code-leaked-via-npm-registry</guid><description>Anthropic accidentally exposed proprietary source code for its Claude Code CLI tool on the public npm registry. Analyze the technical impact and risks.</description><pubDate>Wed, 01 Apr 2026 00:43:28 GMT</pubDate><category>Anthropic</category><category>Claude Code</category><category>NPM</category><category>Source Code Leak</category><category>DevSecOps</category></item><item><title>Securing Claude Code: Managing AI Agent Risk with Ceros Visibility</title><link>https://runtimerebel.com/blog/securing-claude-code-managing-ai-agent-risk-with-ceros-visibility</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-claude-code-managing-ai-agent-risk-with-ceros-visibility</guid><description>Discover how Claude Code creates new security challenges for engineering teams and how Ceros provides the visibility needed to govern autonomous AI agents.</description><pubDate>Thu, 19 Mar 2026 12:18:21 GMT</pubDate><category>Anthropic</category><category>Claude Code</category><category>AI Security</category><category>Ceros</category><category>Governance</category></item><item><title>Claude Code Weaponized in Mexican Government Cyberattack</title><link>https://runtimerebel.com/blog/claude-code-weaponized-in-mexican-government-cyberattack</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-code-weaponized-in-mexican-government-cyberattack</guid><description>Analysis of how threat actors leveraged Anthropic’s Claude Code to automate exploitation and exfiltrate 150GB of data from Mexico&apos;s infrastructure ministry.</description><pubDate>Sun, 01 Mar 2026 16:09:27 GMT</pubDate><category>Claude Code</category><category>Anthropic</category><category>Mexico</category><category>Data Breach</category><category>AI Agents</category><category>SICT</category></item><item><title>Claude Code Security Analysis: Assessing AI CLI Assistant Risks</title><link>https://runtimerebel.com/blog/claude-code-security-analysis-assessing-ai-cli-assistant-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-code-security-analysis-assessing-ai-cli-assistant-risks</guid><description>Technical analysis of Anthropic&apos;s Claude Code CLI tool, evaluating its impact on application security and potential for introducing code vulnerabilities.</description><pubDate>Fri, 27 Feb 2026 16:17:21 GMT</pubDate><category>Anthropic</category><category>Claude Code</category><category>AI Security</category><category>DevSecOps</category><category>Secure Coding</category></item><item><title>Anthropic Patches Claude Code Vulnerabilities Enabling Silent Hacking</title><link>https://runtimerebel.com/blog/anthropic-patches-claude-code-vulnerabilities-enabling-silent-hacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-patches-claude-code-vulnerabilities-enabling-silent-hacking</guid><description>Anthropic addressed flaws in Claude Code that allowed attackers to execute arbitrary commands on developer devices via malicious repository configurations.</description><pubDate>Thu, 26 Feb 2026 16:27:39 GMT</pubDate><category>Anthropic</category><category>Claude Code</category><category>RCE</category><category>Prompt Injection</category><category>Developer Security</category><category>Check Point Research</category></item><item><title>Claude Code Flaws Enable RCE &amp; API Key Exfiltration</title><link>https://runtimerebel.com/blog/claude-code-flaws-enable-rce-api-key-exfiltration</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-code-flaws-enable-rce-api-key-exfiltration</guid><description>Multiple security flaws in Anthropic&apos;s Claude Code AI coding assistant allow remote code execution and API credential theft via configuration mechanisms.</description><pubDate>Wed, 25 Feb 2026 20:15:32 GMT</pubDate><category>Claude Code</category><category>Anthropic</category><category>AI</category><category>Remote Code Execution</category><category>API Key Exfiltration</category><category>Vulnerability</category><category>Development Tools</category></item></channel></rss>