Affected Technology
Claude Code incidents
Claude Code agent security and tooling issues
Low severity NEW
Claude Remote Code Execution Vulnerability
Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command
Low severity NEW
Claude Credential Exposure
Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage