CloudSec Wine
2.25K subscribers
1.07K photos
24 files
1.39K links
All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Download Telegram
🌩 All Your Claude Are Belong To Us: Reversing Claude Code's Remote Control Protocol

Researchers reverse-engineered Claude Code's ("claude.exe") undocumented "--sdk-url" flag, fully mapped its CCRv1 WebSocket remote control protocol (NDJSON over WebSockets), and implemented a Python C2 server. The flag accepts arbitrary URLs with no authentication, enabling post-compromise beaconing.

https://www.originhq.com/blog/reversing-remote-control

#ClaudeCode
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1
🌩 My Claude Code Setup (2026 Edition)

A walkthrough of my Claude Code setup across a multi-project monorepo: global settings, safety guardrails, a context/plan/code workflow, subagents and plugins, and the StarCraft-themed customisations that make the terminal feel like mine.

https://blog.marcolancini.it/2026/blog-my-claude-code-setup

#ClaudeCode
Please open Telegram to view this post
VIEW IN TELEGRAM
2👍2🔥2
🌩 Claude Code MCP Token Theft: MitM Attack Explained

Mitiga Labs shows how Claude Code MCP configuration can be hijacked through ~/.claude.json to steal OAuth tokens, persist through rotation, and hide in trusted SaaS activity.

https://www.mitiga.io/blog/claude-code-mcp-token-theft-mitm

#ClaudeCode
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1
🌩 Skill Issues: Compromising Claude Code with malicious skills & agents

With the increasing usage of AI Coding agents, can coding agent skill files be exploited as an initial access mechanism, and how? This is part 1 of a 3 part series exploring the attack surface and defensive recommendations.

https://labs.reversec.com/posts/2026/05/skill-issues-compromising-claude-code-with-malicious-skills-agents-part-1

#ClaudeCode
Please open Telegram to view this post
VIEW IN TELEGRAM
2👍2🔥2
🌩 Automating Security Operations with AI: Triaging Renovate PR

A Claude Code Routine that triages every Renovate PR by risk, flags dead deps, and catches deprecated framework configs before I touch the diff.

https://blog.marcolancini.it/2026/blog-automating-security-operations-with-ai-triage-renovate

#ClaudeCode
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1
🌩 When Background AI Agents Become a Security Boundary Problem

Claude Code's background sessions, supervisor process, CLAUDE_CONFIG_DIR override, scheduled tasks, and Markdown-based agent definitions can be chained post-foothold to deploy a persistent, nearly invisible C2 agent evading standard EDR binary-focused detection.

https://www.originhq.com/research/background-c2-agent

#ClaudeCode
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1
🌩 Hidden Gaps in Claude Code Security Reviews

Claude Code's /security-review is vulnerable to model anchoring bias when run in the same session that wrote the code. A new diff-scoped plugin avoids this but misses cross-commit vulnerability chains where each individual change appears benign in isolation.

https://brainoverflow.blog/posts/claude-code-security-review-bias

#ClaudeCode
Please open Telegram to view this post
VIEW IN TELEGRAM
👍41🔥1
🌩 Securing CI/CD in an agentic world: Claude Code Github action case

Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack chain, responsible disclosure process, Anthropic's mitigation, and guidance for securing AI-powered CI/CD workflows.

https://www.microsoft.com/en-us/security/blog/2026/06/05/securing-ci-cd-in-agentic-world-claude-code-github-action-case

#ClaudeCode
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
👍31🔥1