Vulnerabilities & Exploits
Two separate disclosures show AI coding assistants and local developer servers can be abused: Claude Code's default-trust agent behavior enables repo-based RCE, while Cline Kanban v0.1.59 exposes local WebSocket endpoints to cross-origin attacks.
6 sources · May 8
CSO Online
Pen tests show AI security flaws far more severe than legacy software bugs
Penetration tests of AI systems expose significantly higher severe-flaw density when compared to legacy apps. New attack surfaces, larger blast radii, and unclear remediation ownership compound the risks.
originalThe Register Security
Anthropic response to 1-click pwn: Shouldn't have clicked 'ok'
Security biz Adversa AI argues users of AI tools need clearer warnings
originalMicrosoft Security Blog
When prompts become shells: RCE vulnerabilities in AI agent frameworks | Microsoft Security Blog
Learn how these vulnerabilities work, what’s impacted, and how to secure your agents.
originalPart of the PlainSec briefing for 2026-05-07
Every edition of this story: Anthropic Claude Code security update