Skip to main content
Security

Researcher reports Claude Code web-summary chain leading to code execution

Researcher reports Claude Code web-summary chain leading to code execution Image: Primary
A security researcher reported that Claude Code running Opus 5 in Auto Mode could be induced to execute attacker-controlled code after being asked to summarize a webpage. The reported chain made WebFetch fail, redirected the agent to a ZIP archive, and relied on a malicious local Python module being imported when the agent wrote its own decoder. The researcher said three tested variants succeeded in 60% to 80% of five attempts each. Anthropic reportedly described Auto Mode as a convenience feature rather than a security guarantee.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Next Web and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

SonicWall reports exploited SMA1000 zero-days and releases fixes

SecurityWeek reported that SonicWall urged SMA1000 customers to patch two zero-day vulnerabilities the vendor says have been exploited. CVE-2026-83548 is a pre-authentication SSRF flaw in the Appliance Work Place interface that ca...

Security AI
Security AI

Langflow flaw is being exploited to harvest cloud and AI credentials

Threat actors are exploiting CVE-2026-0768, an unauthenticated remote-code-execution flaw in Langflow's custom-component code validator, to steal credentials, tokens and keys, according to VulnCheck observations reported by Bleepi...

Security
Security

Attackers exploit Artifactory authentication-bypass flaw

Threat actors began exploiting CVE-2026-82329 in JFrog Artifactory on September 1, according to watchTowr. The critical authentication-bypass flaw can allow an unauthenticated network attacker to obtain administrative privileges u...

AI Security
AI Security

OpenAI says Astra reached its critical cyber-capability threshold

OpenAI says its forthcoming Astra model has reached the company's threshold for critical cyber capabilities, defined as independently finding and exploiting previously unknown vulnerabilities in real-world software. The company p...