DeFi Daily News
Saturday, June 27, 2026
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home DeFi Web 3

rewrite this title Claude Code Vulnerability Could Let Attackers Steal Credentials From GitHub, Says Microsoft – Decrypt

Jason Nelson by Jason Nelson
June 6, 2026
in Web 3
0 0
0
rewrite this title Claude Code Vulnerability Could Let Attackers Steal Credentials From GitHub, Says Microsoft – Decrypt
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

In brief

Microsoft researchers found that Anthropic’s Claude Code GitHub Action could be manipulated through prompt injection attacks.
The attack relied on malicious instructions hidden in GitHub issues, pull requests, or comments that the AI agent was asked to review.
Anthropic patched the vulnerability in May after Microsoft disclosed the issue through HackerOne.

Microsoft researchers disclosed a now-patched vulnerability in Anthropic’s Claude Code GitHub Action that could have allowed attackers to expose credentials stored in software development pipelines by manipulating the AI agent through malicious GitHub content.

In a blog post on Friday, Microsoft warned that AI coding agents running inside CI/CD workflows may create new security risks because those environments often have access to API keys, cloud credentials, and other sensitive information.

“We began this research after observing prompt injection attempts in public repositories using AI-assisted GitHub workflows across multiple vendors, where attacker-controlled issue or [pull requests], content is processed by the AI agent and could influence its tool use,” Microsoft wrote.

On GitHub, a pull request allows developers to propose changes to a code repository and have those changes reviewed before they are approved and merged.



The report comes as prompt injection attacks have emerged as one of the biggest security threats facing AI agents. In a prompt injection attack, an attacker hides instructions in content such as emails, documents, websites, or code comments, causing an AI system to follow those instructions instead of the user’s.

Launched in October, Claude Code is Anthropic’s AI coding agent for software development tasks. The tool drew scrutiny in March after Anthropic accidentally leaked more than 500,000 lines of its source code, exposing details of its internal architecture and prompting widespread analysis by researchers and developers.

According to Microsoft, attackers could use prompt injection attacks hidden in GitHub issues, pull requests, or comments to manipulate Claude Code into accessing files containing sensitive credentials.

To test the vulnerability, Microsoft created a GitHub workflow and disguised malicious instructions behind content hosted on a domain it controlled, allowing the researchers to bypass Claude’s safety protections. The prompt injection attack tricked Claude into reading sensitive credentials and altering them to evade both Claude’s safeguards and GitHub’s secret-scanning tools. Microsoft said an attacker could then reconstruct the credential and exfiltrate it through issue comments, workflow logs, web requests, or shell commands.

“To bypass Sonnet’s refusal safety mechanisms, we obscured the shell payload behind a response from our controlled domain,” the firm said. “We also enabled the workflow to be triggered by users with no ‘write’ permissions to ensure Anthropic’s environment variables scrub mitigations were active during our tests.”

Anthropic patched the flaw on May 5 with Claude Code version 2.1.128 after Microsoft disclosed the vulnerability through HackerOne on April 29.

Despite multiple layers of built-in security controls, Microsoft found that a determined attacker could potentially manipulate an AI agent into exposing sensitive information.

“We are entering an era where natural language is executable code, and untrusted inputs like GitHub issues must be treated as hostile by default,” it said. “A single, carefully crafted comment combined with a misunderstood trust boundary is all it takes to walk away with production credentials.”

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website http://defi-daily.com and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: AttackersClaudeCodecredentialsDecryptGithubMicrosoftrewriteStealtitlevulnerability
ShareTweetShare
Previous Post

rewrite this title Has Ethereum (ETH) Price Finally Bottomed? Here’s Where It Could Head in June 2026

Next Post

rewrite this title Spencer Pratt's Race for Mayor Shows How Climate Disasters Can Fuel Anti-Establishment Politics

Next Post
rewrite this title Spencer Pratt's Race for Mayor Shows How Climate Disasters Can Fuel Anti-Establishment Politics

rewrite this title Spencer Pratt's Race for Mayor Shows How Climate Disasters Can Fuel Anti-Establishment Politics

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
rewrite this title Will the Next Bilt Credit Card Please Stand Up? – NerdWallet

rewrite this title Will the Next Bilt Credit Card Please Stand Up? – NerdWallet

March 18, 2025
How one terrible trip inspired a tech IPO: Navan Co-Founder

How one terrible trip inspired a tech IPO: Navan Co-Founder

June 15, 2026
rewrite this title ‘My Neighbor Alice’ Launches 100K ALICE Grant Program To Support Web3 Development And Ecosystem Growth

rewrite this title ‘My Neighbor Alice’ Launches 100K ALICE Grant Program To Support Web3 Development And Ecosystem Growth

April 21, 2025
rewrite this title AO Offshores Bulk of Customer Service Jobs to South Africa in Savings Drive – UC Today

rewrite this title AO Offshores Bulk of Customer Service Jobs to South Africa in Savings Drive – UC Today

June 19, 2026
Baylor QB Sawyer Robertson | Gruden’s QB Class

Baylor QB Sawyer Robertson | Gruden’s QB Class

April 20, 2026
Polygon Labs Reveals Rebranding of MATIC Token to POL in September, Accompanied by Significant Technical Enhancements – The Daily Hodl

Polygon Labs Reveals Rebranding of MATIC Token to POL in September, Accompanied by Significant Technical Enhancements – The Daily Hodl

July 20, 2024
rewrite this title Engadget review recap: MSI Claw 8 EX AI+, Sony A7R VI, Ray-Ban Meta Optics and more – Engadget

rewrite this title Engadget review recap: MSI Claw 8 EX AI+, Sony A7R VI, Ray-Ban Meta Optics and more – Engadget

June 27, 2026
rewrite this title and make it good for SEOBlue Owl: The Market Is Still Pricing In An Earnings Collapse (NYSE:OWL)

rewrite this title and make it good for SEOBlue Owl: The Market Is Still Pricing In An Earnings Collapse (NYSE:OWL)

June 27, 2026
rewrite this title The Great Wallet Shift and Why Seed Phrases May Disappear

rewrite this title The Great Wallet Shift and Why Seed Phrases May Disappear

June 27, 2026
rewrite this title England defensive issues: Thomas Tuchel must iron out backline problems before tougher tests await in World Cup knock-outs

rewrite this title England defensive issues: Thomas Tuchel must iron out backline problems before tougher tests await in World Cup knock-outs

June 27, 2026
rewrite this title and make it good for SEO Binance Faces EU Service Curbs as MiCA Deadline Nears

rewrite this title and make it good for SEO Binance Faces EU Service Curbs as MiCA Deadline Nears

June 27, 2026
rewrite this title Outdated bank rules may keep crypto outside the banks now allowed to hold it

rewrite this title Outdated bank rules may keep crypto outside the banks now allowed to hold it

June 27, 2026
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.