NewsSANS NewsBites2026-04-01 00:00 UTC
Claude Code Source Code Exposed — Beware Fake Leaks and Check for Axios Compromise
NEOSEC enrichment — no mirror of the original source
On Tuesday, March 31, 2026, Anthropic accidentally published the source code for their agentic command-line tool Claude Code within version 2.1.88 released on npm, due to the inclusion of a source map file intended for debugging. While Anth
Source: SANS NewsBites. For licensing reasons NEOSEC Intel does not mirror the full text verbatim. Full body and expert context live with the original.
Read the issue at SANS NewsBites →More on Exposed
Other advisories
- ghsa:GHSA-68w4-83fh-f2w8highpyload-ng: getUserData/get_userdata exposed at Perms.ANY allow any authenticated account to brute-force the administrator password
- osv:GHSA-68w4-83fh-f2w8nonepyload-ng: getUserData/get_userdata exposed at Perms.ANY allow any authenticated account to brute-force the administrator password
- CVE-2026-61426nonePraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure
- CVE-2026-61426highPraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure
- osv:CLEANSTART-2026-WL07802noneundici's retry handler can leave an already-exposed response body pending forever
- osv:CLEANSTART-2026-HI60053noneundici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response
- osv:CLEANSTART-2026-AY31255noneSpring RSocket application is exposed to a memory leak via a malformed SETUP frame
- CVE-2026-106499mediumBackstage: Secret-derived values may be exposed in scaffolder task logs
Other news entries
- Newsbleepingcomputer2026-10-10Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management
- Newscsoonline2026-10-09Exposed Nvidia GPU monitors can reveal AI infrastructure secrets
- Newssecurityweek2026-10-09In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years
- Newstheregister-security2026-10-08High-severity Nvidia bug could crash GPU monitoring on exposed servers
- Newsthehackernews2026-10-08ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
- Newscsoonline2026-10-08FBI: FortiBleed attackers can lock organizations out of their own firewalls
- Newsbleepingcomputer2026-10-07FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
- Newsthehackernews2026-10-07PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Source: https://www.zscaler.com/
ID