Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Tego AI Reveals Second Security Issue in Claude Software

Tego AI Reveals Second Security Issue in Claude Software

Posted on July 24, 2026 By CWS

Tel Aviv, Israel, July 24th, 2026, CyberNewswire — Tego AI, a cybersecurity firm, has disclosed a second vulnerability within a week in Anthropic’s Claude ecosystem, focusing this time on the Claude Code tool. This disclosure follows a previous revelation about a flaw in the Claude Tag Slack integration.

The issue arises when Claude Code, a command-line coding tool, processes an external file without user awareness. This can occur when a repository is cloned, and Claude Code is initiated, leading to the automatic inclusion of an external file in the model’s initial request.

How the Vulnerability Works

The exploitation method is straightforward. By committing a file named CLAUDE.md, containing an @import directive that points to a symbolic link, developers can inadvertently expose external files. Upon cloning the repository and launching Claude Code, the tool follows the symbolic link to the specified file, incorporating its contents into the initial request made to the model, without triggering any alerts or requiring user approval.

This occurs because Claude Code’s security checks focus on in-repository links rather than the external files they may resolve to. Consequently, the contents of the external file become part of an outbound request, leaving the user’s system without their explicit consent.

Security Implications and Previous Fixes

Tego AI emphasizes the importance of this discovery due to its potential security implications. Similar flaws were previously identified and resolved in Claude Code under CVE-2025-59829 and CVE-2026-25724. However, this new report highlights that another code path, the startup memory loader, remains vulnerable, allowing unauthorized file access before any model actions.

Anthropic has recognized the issue but maintains that their security model, which relies on the ‘trust this folder’ prompt, is intact. This model assumes that accepting the prompt grants extensive permissions, aligning with their threat model.

Industry Response and Future Considerations

Tego AI’s disclosure is part of a broader discussion on security boundaries within AI tools. The company argues that the current model places excessive trust on a single user action, which might not sufficiently differentiate between benign and malicious operations.

Anthropic’s rationale for closing the report as ‘Informative’ reflects their consistent application of the security model. However, Tego AI stresses the need for enterprises to carefully evaluate these boundaries as AI coding agents become more prevalent.

Symbolic link attacks are not new, but Tego AI’s findings urge users and security teams to reassess the implications of granting trust to repository folders. The complete technical report is available for further insights.

About Tego AI

Tego AI specializes in cybersecurity for enterprise AI agents, focusing on runtime security and control. Their platform aims to prevent unauthorized actions by monitoring agent activities before accessing sensitive resources. Operating in stealth, Tego AI continues to reveal significant security issues, with more disclosures anticipated.

Cyber Security News Tags:AI agents, AI tools, Anthropic, Claude Code, Cybersecurity, developer security, GitHub, HackerOne, Repository, runtime security, security flaw, symbolic link, Tego AI

Post navigation

Previous Post: SourTrade Malvertising Evades Detection with Unique Malware

Related Posts

Biggest Ever GreedyBear Attack With 650 Hacking Tools Stolen  Million from Victims Biggest Ever GreedyBear Attack With 650 Hacking Tools Stolen $1 Million from Victims Cyber Security News
Mocha Manakin Using Paste and Run Technique to Trick Users Into Downloading Malicious Payloads Mocha Manakin Using Paste and Run Technique to Trick Users Into Downloading Malicious Payloads Cyber Security News
U.S. Government Seizes Online Marketplaces Used to Sell Fraudulent Identity Documents to Cybercriminals U.S. Government Seizes Online Marketplaces Used to Sell Fraudulent Identity Documents to Cybercriminals Cyber Security News
Russian Ransomware Operator Sentenced to 102 Months Russian Ransomware Operator Sentenced to 102 Months Cyber Security News
New Data Leak Site Linked to Active Cyber Threat New Data Leak Site Linked to Active Cyber Threat Cyber Security News
Critical Jenkins Security Flaws Threaten Server Safety Critical Jenkins Security Flaws Threaten Server Safety Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11
  • Golden Chickens Unveils New Malware Threats
  • Cl0p Hackers Target Windchill Servers for Data Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11
  • Golden Chickens Unveils New Malware Threats
  • Cl0p Hackers Target Windchill Servers for Data Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark