Claude Code has a flaw in its startup memory loader related to handling symbolic links (symlinks) that can unintentionally expose readable files from outside a cloned repository, without requiring explicit user approval. The issue arises not from the tool following symlinks, something that is standard behavior in filesystems, but from a mismatch in how its […]
The post Claude Code Symlink Flaw Exfiltrates Sensitive Files Without User Approval appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

AsyncAPI Malware Contains Modules to Steal GitHub, npm, Cloud and AI API Credentials
A dangerous supply chain attack struck the AsyncAPI project on the npm registry, putting developers and automated build systems at risk. Attackers republished five package


