Claude Code-ல் Critical Vulnerabilities — Remote Code Execution மற்றும் API Key திருடல்: AI Coding Tool-ன் ஆபத்தான பக்கம்
AI coding assistants உலகம் முழுவதும் developers-க்கு இன்றியமையாத tools ஆகிவிட்டன. ஆனால் நீங்கள் நம்பும் tool-ஆல் உங்கள் development environment compromise ஆனால்? Check Point Research அந்த கேள்விக்கு பதிலளித்துள்ளது: Anthropic-ன் Claude Code-ல் இரண்டு critical vulnerabilities — CVE-2025-59536 மற்றும் CVE-2026-21852 — developer ஒரு malicious repository clone செய்தால் remote code execution மற்றும் API credentials திருடல் சாத்தியம்.
இது theoretical attack அல்ல. Claude Code-ன் legitimate features — Hooks, Model Context Protocol (MCP) servers, environment variables — ஐ ஆயுதங்களாக மாற்றி, developer untrusted project open செய்த கணமே arbitrary shell commands execute செய்து Anthropic API keys exfiltrate செய்கின்றன.
Premium Content
You've read all your free articles today. Subscribe to continue reading.
You've used 3 of 3 free articles today.
Subscribe NowAlready subscribed? Sign in




கருத்துகள் (0)
Be the first to comment!