Skip to content
AI Primer
TOPIC15 stories

Security

Stories, products, and related signals connected to this tag in Explore.

NEWS25th August
Researcher finds phishing-link injection in ChatGPT Trusted Contact emails

A researcher reports that attacker-controlled recipient names can insert phishing links into authenticated ChatGPT Trusted Contact invitations. The flaw could place a malicious link inside an email sent from OpenAI.

NEWS3w ago
Anthropic engineer claims Claude Code defaults can hit 0% prompt-injection success

Benjamin Cherny said Anthropic trains Claude against prompt injection and that Claude Code’s model, probe, and auto-mode layers can reach 0% attack success in next week’s defaults. The claim comes from an Anthropic engineer rather than an independent benchmark.

NEWS3w ago
Anthropic fixes Claude Code proxy false account flags

Anthropic’s Boris Cherny said Claude Code users are not banned for using other model harnesses through proxies. He pointed to a classifier issue, unblocked one escalated account, and said false positives are being reduced.

RELEASE3w ago
Claude Code makes Auto Mode default for paid users on Aug. 14

Anthropic says Claude Code Pro, Max, and Team users will default to Auto Mode on Aug. 14. Its tool-call classifier reportedly caught 89% of dangerous commands, versus 14% for manual approval, after prompt-injection testing.

WORKFLOW4w ago
Developers propose scoped password access for Codex, Devin, Claude, and Cursor

Developers proposed agent-specific browser auth for Codex, Devin, Claude, and Cursor so agents can use selected passkeys, TOTPs, and passwords without exposing full vaults. Related posts warned that Claude Connectors may broaden tool access.

WORKFLOW4w ago
AI app builders add review guardrails before merge or publish

Practitioners are putting review steps around AI app builders before merge or publish. Examples include PostHog-to-Cursor Cloud PRs, Bolt's six-category security scan, and a Claude Code prompt that inspects repos first.

NEWS1mo ago
Users report Claude shared links indexed by Google Search

Viral posts claim public Claude chats and artifacts were indexed by search engines. Examples allegedly include API keys, resumes, legal notes, dashboards, project plans, and medical summaries.

NEWS1mo ago
Fake Float Bro AI videos drive shoppers to Shopify storefronts

Venturetwins traced viral AI videos for a fake “Float Bro” product to Shopify storefronts with AI product images, checkout flows, paid coverage, and fake review videos. The campaign tied AI-generated product media to working commerce funnels.

RELEASE1mo ago
xAI opens Grok Build CLI repo and resets usage limits

xAI released the Grok Build CLI repo and reset usage limits. It says zero data retention was respected, default retention was turned off July 12, and previously retained coding data is being deleted.

WORKFLOW1mo ago
AgenticSeek guide ships local agent stack with Ollama, SearXNG, and Docker

Hasantoxr documents AgenticSeek with Ollama, SearXNG, and Docker, including install steps, model config, and a locked WORK_DIR. The stack keeps models, chats, and files on the user's machine.

NEWS2mo ago
Anthropic removes Fable 5 and Mythos 5 access after US directive

Anthropic said a US government directive forced it to disable Fable 5 and Mythos 5 across Claude products and APIs. The change also pushed Build Day and downstream tooling to Opus 4.8, breaking active Fable sessions and triggering fallbacks in tools like Linear Agent.

NEWS2mo ago
Anthropic introduces visible Fable 5 fallback after Mythos complaints

Anthropic said flagged Fable 5 requests will now visibly fall back to Opus 4.8, and API refusals will return reasons instead of silently degrading output. The update matters because users were reporting sudden quality drops, opaque refusals, and quota-burn confusion around Mythos-class safeguards.

RELEASE3mo ago
Claude Code ships Security Guidance plugin: 30-40% fewer PR security comments

Anthropic released a Security Guidance plugin for Claude Code through the plugin marketplace and said internal use cut security-related PR comments by 30-40%. Teams can also enforce repo or MDM-distributed claude-security-guidance.md rules, making Claude Code a first-pass policy check before review.

NEWS4mo ago
OpenAI reports 20M-log ChatGPT handover after May-Sep 2025 preservation order

Posts citing court filings said OpenAI had to preserve deleted ChatGPT and some non-ZDR API logs from May to September 2025 and later hand over 20 million de-identified chats in the NYT case. The issue matters because deleted chats were not immediately gone for affected users, including people storing sensitive creative or client work in ChatGPT.

RELEASE4mo ago
Claude Code adds /ultrareview with 3 free cloud reviews through May 5

Claude Code introduced /ultrareview in research preview, sending parallel bug-hunting agents to scan critical changes and return findings in the CLI or Desktop. That matters because Pro and Max users get three free runs through May 5, and analysis threads frame it as a lower-noise answer to conventional AI review false positives.

AI PrimerAI Primer

Your daily guide to AI tools, workflows, and creative inspiration.

© 2026 AI Primer. All rights reserved.