Security
Stories, products, and related signals connected to this tag in Explore.
Stories
Filter storiesA researcher reports that attacker-controlled recipient names can insert phishing links into authenticated ChatGPT Trusted Contact invitations. The flaw could place a malicious link inside an email sent from OpenAI.
Benjamin Cherny said Anthropic trains Claude against prompt injection and that Claude Code’s model, probe, and auto-mode layers can reach 0% attack success in next week’s defaults. The claim comes from an Anthropic engineer rather than an independent benchmark.
Anthropic’s Boris Cherny said Claude Code users are not banned for using other model harnesses through proxies. He pointed to a classifier issue, unblocked one escalated account, and said false positives are being reduced.
Anthropic says Claude Code Pro, Max, and Team users will default to Auto Mode on Aug. 14. Its tool-call classifier reportedly caught 89% of dangerous commands, versus 14% for manual approval, after prompt-injection testing.
Developers proposed agent-specific browser auth for Codex, Devin, Claude, and Cursor so agents can use selected passkeys, TOTPs, and passwords without exposing full vaults. Related posts warned that Claude Connectors may broaden tool access.
Practitioners are putting review steps around AI app builders before merge or publish. Examples include PostHog-to-Cursor Cloud PRs, Bolt's six-category security scan, and a Claude Code prompt that inspects repos first.
Viral posts claim public Claude chats and artifacts were indexed by search engines. Examples allegedly include API keys, resumes, legal notes, dashboards, project plans, and medical summaries.
Venturetwins traced viral AI videos for a fake “Float Bro” product to Shopify storefronts with AI product images, checkout flows, paid coverage, and fake review videos. The campaign tied AI-generated product media to working commerce funnels.
xAI released the Grok Build CLI repo and reset usage limits. It says zero data retention was respected, default retention was turned off July 12, and previously retained coding data is being deleted.
Hasantoxr documents AgenticSeek with Ollama, SearXNG, and Docker, including install steps, model config, and a locked WORK_DIR. The stack keeps models, chats, and files on the user's machine.
Anthropic said a US government directive forced it to disable Fable 5 and Mythos 5 across Claude products and APIs. The change also pushed Build Day and downstream tooling to Opus 4.8, breaking active Fable sessions and triggering fallbacks in tools like Linear Agent.
Anthropic said flagged Fable 5 requests will now visibly fall back to Opus 4.8, and API refusals will return reasons instead of silently degrading output. The update matters because users were reporting sudden quality drops, opaque refusals, and quota-burn confusion around Mythos-class safeguards.
Anthropic released a Security Guidance plugin for Claude Code through the plugin marketplace and said internal use cut security-related PR comments by 30-40%. Teams can also enforce repo or MDM-distributed claude-security-guidance.md rules, making Claude Code a first-pass policy check before review.
Posts citing court filings said OpenAI had to preserve deleted ChatGPT and some non-ZDR API logs from May to September 2025 and later hand over 20 million de-identified chats in the NYT case. The issue matters because deleted chats were not immediately gone for affected users, including people storing sensitive creative or client work in ChatGPT.
Claude Code introduced /ultrareview in research preview, sending parallel bug-hunting agents to scan critical changes and return findings in the CLI or Desktop. That matters because Pro and Max users get three free runs through May 5, and analysis threads frame it as a lower-noise answer to conventional AI review false positives.