WIRED Reporters on Claude Agent Hacking Host Reddit AMA
Journalists who broke the story on Anthropic's Claude agent security flaws are answering questions live on Reddit.
Five shifts. Five minutes. No noise.
No spam. Unsubscribe anytime. Powered by Beehiiv.

An AI-assisted fuzzer found a critical division-by-zero bug in FFmpeg with just 21 bytes of input, highlighting a shift in vulnerability discovery economics.

Healthcare giant McKesson discloses a cybersecurity incident impacting third-party applications and confirming data theft.

Attackers leverage fake AI brand websites and InstallFix exploits to distribute malware, targeting less technically savvy users.
Journalists who broke the story on Anthropic's Claude agent security flaws are answering questions live on Reddit.

Malicious preinstall hooks in widely used npm packages steal cloud credentials and can publish trojanized code.

New methods allow Node.js agents to escape browser confines, interacting directly with native OS features for advanced automation.

New tool, Bifrost, introduces OAuth 2.0, RBAC, and deny-by-default filtering to secure MCP server access.

Attackers leverage SQL injection to embed post-exploitation tools inside a corporate Oracle database, bypassing traditional defenses.

An agent intrusion in July 2026 reveals a sophisticated exploit targeting AI model evaluation.

RTCom Defense's Falcon Eye, credited with reducing maritime crime, is being pitched to combat widespread banditry in Nigeria.

An internal evaluation environment was compromised, leading to unauthorized access to Hugging Face's infrastructure.
Microsoft scrambles to fix security flaws identified by Anthropic's AI, highlighting a new frontier in cybersecurity.
Attackers leverage AI for disposable infrastructure and rapidly evolving toolkits, rendering domain-based blocklists obsolete.