Disclosure
🚀 Top 10 AI & Dev News of the Day! 🧵👇
🚨 Claude Code RCE Flaws: Check Point Research discovered critical vulnerabilities (like CVE-2025-59536) in Claude Code that allow remote code execution and API key theft simply by opening malicious repositories. https://www.bankinfosecurity.com/malicious-repo-files-could-hijack-claude-code-sessions-a-30854
⚠️ Gemini API Data Leaks: Legacy public Google Cloud API keys (like Maps or Firebase) are silently inheriting unauthorized access to Gemini endpoints, exposing private files and creating massive billing risks. https://ift.tt/JiALlab
⚔️ Anthropic Defies the Pentagon: CEO Dario Amodei publicly rejected the DoD's ultimatum, refusing to drop Claude's safety guardrails against autonomous lethal weapons and mass domestic surveillance. https://ift.tt/hL2AqHi
🐛 MCP Go SDK Vulnerability: Upgrade to v1.3.1 immediately! A high-severity flaw (CVE-2026-27896) allows attackers to bypass security filters due to case-insensitive JSON parsing. https://ift.tt/0QNCImq
📱 Claude Code Remote Control: Anthropic launched a highly-requested feature letting developers seamlessly control and monitor their local terminal coding sessions directly from their phones. https://ift.tt/u3OLgIP
🤖 Microsoft Copilot Tasks: Microsoft unveiled an autonomous background agent that plans and executes multi-step workflows (like calendar management or web research) across different apps without constant human input. https://ift.tt/SdL6NjA
🤝 Copilot Welcomes Claude & Codex: GitHub Copilot Pro and Business users can now select Anthropic's Claude and OpenAI's Codex as their coding agents directly inside VS Code at no extra cost. https://ift.tt/C8WUYGR
🛡️ MCP Server Security Audit: An independent scan of the top 20 Model Context Protocol (MCP) servers revealed that 60% contain real vulnerabilities, including critical arbitrary command execution flaws in Kubernetes servers. https://ift.tt/WrzYOle
🎨 Figma integrates OpenAI Codex: Figma launched a new workflow via its MCP server that connects its infinite design canvas directly to Codex, allowing teams to seamlessly translate UI designs into code. https://ift.tt/I3MuOlk
🖼️ Google's Nano Banana 2: Google shipped Gemini 3.1 Flash Image, crushing the competition by taking the #1 spot on text-to-image leaderboards while costing half the price of Pro models. https://www.latent.space/p/ainews-nano-banana-2-aka-gemini-31
#AI #MachineLearning #CyberSecurity #SoftwareDevelopment #TechNews #WebDev #OpenAI #Anthropic #GitHubCopilot
Post summary
The tweet discloses several new CVEs with technical details and urges a patch for one vulnerability, but does not confirm active exploitation or provide exploit code.