‘Agentic coding tools have access to everything they need for this’: Security experts warn Claude Code can be exploited simply by trying to be helpful
‘Agentic coding tools have access to everything they need for this’: Security experts warn Claude Code can be exploited simply by trying to be helpful

A hidden DNS record tricked Claude Code into opening a reverse shell during routine error recovery, bypassing every standard security scanning tool completely.

‘Advances in quantum research and development have shifted the risk horizon’: Microsoft says it is ramping up its quantum computing security work

Microsoft plans a broad post-quantum migration by 2029 as concerns over future decryption risks increase globally.

Alibaba reportedly bans employees from using Claude Code

Alibaba has reportedly classified Claude Code as high-risk software.

Security Roundup: Apple’s Hide My Email Service Fails to Hide Your Email

Plus: Alleged Scattered Spider hacking member extradited, dozens of license plate reader errors, and Indian officials are concerned about WhatsApp’s username rollout.

Alibaba bans Claude Code after Anthropic is caught tracking Chinese users with hidden code
Alibaba bans Claude Code after Anthropic is caught tracking Chinese users with hidden code

Alibaba has banned its employees from using Claude Code, Anthropic’s AI-powered coding agent, after security researchers discovered that the tool contained hidden code designed to identify Chinese users. The ban, effective 10 July, follows weeks of esc…

The man who built Pegasus now sells governments the antidote, and Latin America is buying
The man who built Pegasus now sells governments the antidote, and Latin America is buying

Dream, the Israeli AI cybersecurity startup that tripled its valuation to $3 billion this year, is expanding into Latin America. The company is targeting governments aligned with Washington in a region where cyber attacks are reportedly growing 25% ann…

North Korea-linked npm packages impersonate Rollup polyfill tools to steal developer secrets
North Korea-linked npm packages impersonate Rollup polyfill tools to steal developer secrets

Security researchers at JFrog have identified a set of malicious npm packages linked to North Korean threat actors that impersonate legitimate Rollup polyfill tooling to steal developer credentials and enable remote access to compromised machines. The …

The emails that broke Anthropic and the Pentagon apart
The emails that broke Anthropic and the Pentagon apart

For months, the fight between Anthropic and the Pentagon looked like a row over access to Claude. Court documents released this week suggest it was about something bigger: who decides how the US military uses frontier AI. The emails came out on Tuesday…

Spain’s LALIGA piracy blocks knocked out 500,000+ innocent websites
Spain’s LALIGA piracy blocks knocked out 500,000+ innocent websites

For much of this year, Spanish internet users have lost access to huge parts of the web on match days. Not pirate streams, but human rights groups, climate charities and business tools. A new report puts hard numbers on the damage, and they are stagger…

GoDaddy warns India’s fake-site crackdown could damage the internet
GoDaddy warns India’s fake-site crackdown could damage the internet

The world’s biggest seller of website addresses says a court order in India could make the internet less safe. GoDaddy is fighting new rules meant to stop fake sites impersonating famous brands. It warns the cure could expose millions of legitimate sit…