Cryptocnews-Crypto News, Cryptocurrency News, Blockchain News, NFT News
    What's Hot

    British Teen Sanctioned By Russia After Alleging Crypto Use to Evade Sanctions

    06/06/2026

    Hyperliquid’s UK warning reveals the regulatory test behind its Wall Street push

    06/06/2026

    ZEC Crashes 38% as Zcash Discloses ‘Critical Counterfeiting Vulnerability’

    06/06/2026
    Facebook Twitter Instagram
    • Business
    • Markets
    • Get In Touch
    • Our Authors
    Facebook Twitter Instagram
    Cryptocnews-Crypto News, Cryptocurrency News, Blockchain News, NFT News
    • Home
    • Business

      Cardano extends weekly losses beyond 30% despite community activity surge

      06/06/2026

      Zcash Suffers Historic Collapse As Billions Vanish From Market Value

      06/06/2026

      AI Is Helping Discover Tech Vulnerabilities—And Zcash Is Just the Latest Example

      06/06/2026

      BitMEX co-founder, Arthur Hayes, liquidates all his ZEC, HYPE, and NEAR tokens

      06/05/2026

      Bitcoin Drops To $59,000 For First Time Since 2024: Crypto’s Total Value Sheds $2 Trillion Since October

      06/05/2026
    • Technology
      1. Business
      2. Insights
      3. View All

      Cardano extends weekly losses beyond 30% despite community activity surge

      06/06/2026

      Zcash Suffers Historic Collapse As Billions Vanish From Market Value

      06/06/2026

      AI Is Helping Discover Tech Vulnerabilities—And Zcash Is Just the Latest Example

      06/06/2026

      BitMEX co-founder, Arthur Hayes, liquidates all his ZEC, HYPE, and NEAR tokens

      06/05/2026

      Cardano extends weekly losses beyond 30% despite community activity surge

      06/06/2026

      Vitalik Wants to Kill DeFi’s Liquidation Problem

      06/06/2026

      The Next Bitcoin ETF Boom May Be Coming From Japan, Here’s Why

      06/06/2026

      Bitcoin Reserves Resuscitation, Iran War Falls Into The Background, But What’s Going On With BTC?

      06/06/2026

      Hyperliquid’s UK warning reveals the regulatory test behind its Wall Street push

      06/06/2026

      ZEC Crashes 38% as Zcash Discloses ‘Critical Counterfeiting Vulnerability’

      06/06/2026

      Cardano extends weekly losses beyond 30% despite community activity surge

      06/06/2026

      Cardano founder floats splitting his own blockchain after warning more apps will die

      06/05/2026
    • Insights
      1. Bitcoin
      2. Ethereum
      3. Eurozone
      4. Monero
      5. View All

      Cardano extends weekly losses beyond 30% despite community activity surge

      06/06/2026

      BitMEX co-founder, Arthur Hayes, liquidates all his ZEC, HYPE, and NEAR tokens

      06/05/2026

      XLM extends losses as weak retail demand weighs on sentiment

      06/04/2026

      Real Finance, Anchorage Digital partner to expand RWA infrastructure

      06/03/2026

      Cardano extends weekly losses beyond 30% despite community activity surge

      06/06/2026

      Vitalik Wants to Kill DeFi’s Liquidation Problem

      06/06/2026

      BitMEX co-founder, Arthur Hayes, liquidates all his ZEC, HYPE, and NEAR tokens

      06/05/2026

      Microsoft Warns AI Chatbot Results Are Being Used in Cryptojacking Campaigns

      06/05/2026

      Cardano extends weekly losses beyond 30% despite community activity surge

      06/06/2026

      BitMEX co-founder, Arthur Hayes, liquidates all his ZEC, HYPE, and NEAR tokens

      06/05/2026

      The Hyperinflation Of 1971 At The Kindergarten

      06/05/2026

      5th Worst Bitcoin Price Action Ever — I’m Buying At 99.8% Probability

      06/05/2026

      Cardano extends weekly losses beyond 30% despite community activity surge

      06/06/2026

      BitMEX co-founder, Arthur Hayes, liquidates all his ZEC, HYPE, and NEAR tokens

      06/05/2026

      XLM extends losses as weak retail demand weighs on sentiment

      06/04/2026

      Real Finance, Anchorage Digital partner to expand RWA infrastructure

      06/03/2026

      Cardano extends weekly losses beyond 30% despite community activity surge

      06/06/2026

      Vitalik Wants to Kill DeFi’s Liquidation Problem

      06/06/2026

      The Next Bitcoin ETF Boom May Be Coming From Japan, Here’s Why

      06/06/2026

      Bitcoin Reserves Resuscitation, Iran War Falls Into The Background, But What’s Going On With BTC?

      06/06/2026
    • Markets
    • Get In Touch
    Cryptocnews-Crypto News, Cryptocurrency News, Blockchain News, NFT News
    Home»Uncategorized»Claude Code Vulnerability Could Let Attackers Steal Credentials From GitHub, Says Microsoft
    Uncategorized

    Claude Code Vulnerability Could Let Attackers Steal Credentials From GitHub, Says Microsoft

    adminBy admin06/06/2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    In brief

    • Microsoft researchers found that Anthropic’s Claude Code GitHub Action could be manipulated through prompt injection attacks.
    • The attack relied on malicious instructions hidden in GitHub issues, pull requests, or comments that the AI agent was asked to review.
    • Anthropic patched the vulnerability in May after Microsoft disclosed the issue through HackerOne.

    Microsoft researchers disclosed a now-patched vulnerability in Anthropic’s Claude Code GitHub Action that could have allowed attackers to expose credentials stored in software development pipelines by manipulating the AI agent through malicious GitHub content.

    In a blog post on Friday, Microsoft warned that AI coding agents running inside CI/CD workflows may create new security risks because those environments often have access to API keys, cloud credentials, and other sensitive information.

    “We began this research after observing prompt injection attempts in public repositories using AI-assisted GitHub workflows across multiple vendors, where attacker-controlled issue or [pull requests], content is processed by the AI agent and could influence its tool use,” Microsoft wrote.

    On GitHub, a pull request allows developers to propose changes to a code repository and have those changes reviewed before they are approved and merged.

    The report comes as prompt injection attacks have emerged as one of the biggest security threats facing AI agents. In a prompt injection attack, an attacker hides instructions in content such as emails, documents, websites, or code comments, causing an AI system to follow those instructions instead of the user’s.

    Launched in October, Claude Code is Anthropic’s AI coding agent for software development tasks. The tool drew scrutiny in March after Anthropic accidentally leaked more than 500,000 lines of its source code, exposing details of its internal architecture and prompting widespread analysis by researchers and developers.

    According to Microsoft, attackers could use prompt injection attacks hidden in GitHub issues, pull requests, or comments to manipulate Claude Code into accessing files containing sensitive credentials.

    To test the vulnerability, Microsoft created a GitHub workflow and disguised malicious instructions behind content hosted on a domain it controlled, allowing the researchers to bypass Claude’s safety protections. The prompt injection attack tricked Claude into reading sensitive credentials and altering them to evade both Claude’s safeguards and GitHub’s secret-scanning tools. Microsoft said an attacker could then reconstruct the credential and exfiltrate it through issue comments, workflow logs, web requests, or shell commands.

    “To bypass Sonnet’s refusal safety mechanisms, we obscured the shell payload behind a response from our controlled domain,” the firm said. “We also enabled the workflow to be triggered by users with no ‘write’ permissions to ensure Anthropic’s environment variables scrub mitigations were active during our tests.”

    Anthropic patched the flaw on May 5 with Claude Code version 2.1.128 after Microsoft disclosed the vulnerability through HackerOne on April 29.

    Despite multiple layers of built-in security controls, Microsoft found that a determined attacker could potentially manipulate an AI agent into exposing sensitive information.

    “We are entering an era where natural language is executable code, and untrusted inputs like GitHub issues must be treated as hostile by default,” it said. “A single, carefully crafted comment combined with a misunderstood trust boundary is all it takes to walk away with production credentials.”

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    British Teen Sanctioned By Russia After Alleging Crypto Use to Evade Sanctions

    06/06/2026

    Cardano extends weekly losses beyond 30% despite community activity surge

    06/06/2026

    Bitcoin Has Dumped All of Its Gains Since Trump Was Reelected—And Then Some

    06/06/2026

    Data of 53,888 People at Risk After Healthcare Firm Breached – Personal, Financial and Health Records Potentially Exposed

    06/06/2026
    Add A Comment

    Leave A Reply Cancel Reply

    Top Posts

    Millennials Are Quitting Job to Become Day Traders

    01/20/2021

    Jack Dorsey Says Bitcoin Will Unite The World

    01/15/2021

    Hong Kong Customs Arrest Four in Crypto Laundering Bust

    01/15/2021

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Demo
    Facebook Twitter Instagram Pinterest YouTube
    Top Insights

    British Teen Sanctioned By Russia After Alleging Crypto Use to Evade Sanctions

    06/06/2026

    Hyperliquid’s UK warning reveals the regulatory test behind its Wall Street push

    06/06/2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © {2025-2026} Copyright CryptocNews.com
    • Home
    • Business
    • Markets
    • Technology
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.