top of page
ALL POSTS
Tego AI Reveals Second Claude Vulnerability in a Week: Hidden Links Covertly Transmit Files to Attackers
Key Findings Tego AI disclosed a second vulnerability in Anthropic's Claude ecosystem within one week, this time affecting Claude Code, the command-line coding tool A malicious repository can use symbolic links in a CLAUDE.md file to trick Claude Code into reading files outside the project directory and sending them to Anthropic's servers without user warning or approval The vulnerability exploits a gap in Anthropic's previous fixes—two similar flaws were patched in CVE-2025-
Jul 243 min read
Four VS Code Extensions with 125M+ Installs Contain Critical Flaws
Key Findings Cybersecurity researchers have disclosed multiple security vulnerabilities in four popular Microsoft Visual Studio Code (VS Code) extensions with over 125 million collective installs. The vulnerable extensions are Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview. If successfully exploited, these vulnerabilities could allow threat actors to steal local files and execute code remotely. The researchers warn that a single malicious exte
Feb 182 min read
bottom of page
