Anthropic’s Claude Code running Opus 5 in Auto Mode can be tricked into executing attacker-controlled code simply by asking the coding agent to summarize a website. The attack works up to 80 percent of the time, according to prompt-injection wizard Johann Rehberger, aka wunderwuzzi. In a blog and video demo, he detailed how to hijack Opus 5 in Auto Mode, which is the default setting for Claude as of mid-August. It starts off by asking the agentic coding model to summarize a malicious website that presents itself as an archive of notebook records, and then tricking Claude into using curl instead of its WebFetch tool to retrieve the contents of the page – but without directly telling the model to use curl. The WebFetch request fails, returning a 415 Unsupported Media Type response, so the model decides to access the website directly by issuing a Bash tool call with curl. The website returns a 303 response, and redirects to a malicious ZIP archive, which Claude then downloads. This archive contains seemingly harmless files including catalog metadata, a README file, seven Base85/zlib-encoded JSON notebook records, a macOS decoder-darwin binary – plus a poisoned Python file named struct.py. Claude, per its safety guardrails, refuses to run the decoder: “This is planned and what the attacker wants,” Rehberger wrote. Instead of using the supplied binary, the AI decides to write its own decoder. “Ironically, that safety decision is the exploit path,” Rehberger explained, adding a purple devil emoji to the text. The new decoder imports base64, and from here the attack relies on Python module shadowing to trick the model into running the malicious struct.py code. Module shadowing occurs when a local file shares the same name as a Python standard-library module. The local file hides the official module, causing Python to load it instead. In this case, the standard-library base64 module imports the legitimate struct module, and the malicious ZIP contains a malicious file with the same name. Rehberger says he used ChatGPT to obfuscate the malicious struct.py code to bypass Claude’s safety controls, and this successfully launches a separate Python process to download and execute a remote payload – in this case a command-and-control callback, which in turn opens Calculator. We assume that real attackers would execute something a little more nefarious. In another attack scenario, struct.py launches a second, headless Claude Code via claude -p, meaning this prompt injection can be used not just to remotely execute code, but rather to create a whole new agent. “The nested Claude gets its own tool access and context,” Rehberger wrote. “In these runs the child performed basic recon (whoami, uname, id), opened Calculator and wrote to local files in the home folder.” Across three variants tested five times each, which Rehberger noted were small samples, he reported success rates between 60 percent and 80 percent. “I would say that these results are representative for a motivated attack, but not comprehensive.” Anthropic did not respond to The Register’s request for comment, but reportedly told Rehberger that the model’s “behavior is working as designed.” We’ve heard this one before. “Auto Mode is a convenience feature backed by a best-effort classifier, not a security guarantee,” Rehberger wrote, paraphrasing Anthropic’s response to his security report. According to Rehberger, the classifier isn’t built to stop determined prompt-injection chains made up of individually benign-looking steps, and the real boundary is OS isolation and network egress control. The key takeaway, according to Rehberger, is to run this and other coding agents in a sandbox. “The solution is something we talked about for many years,” he wrote. “Do not trust the model output.”®
The former Defense Intelligence Agency (DIA) IT specialist previously accused of trying to pass secret and top-secret information to foreign spies has pleaded guilty following a successful FBI sting. Nathan Vilas Laatsch, then 28, and now 29, was arrested in May 2025 after an undercover FBI agent caught him for the second time transmitting intelligence packages in a public park that he believed would be collected by a foreign government’s spy. The man, who had been employed at the DIA as a civilian employee since 2019, held top-secret clearance, and in March 2025 offered to transmit classified information to an overseas administration. The identity of this country has never been revealed, but court documents [PDF] describe it as “a friendly foreign government.” Laatsch was assigned to the DIA’s Insider Threat Division in “spring 2025,” a unit dedicated to identifying government workers who were likely to leak, or already were leaking, classified information to foreign powers. According to the Justice Department, the FBI “became aware” of Laatsch’s offer in March. The man’s initial email, sent from a newly created account, had the subject line: “Outreach from USA Defense Intelligence Agency (DIA) Officer.” The email introduced Laatsch, his role at the DIA, and the service he was willing to provide. According to the complaint, Laatsch served in a technical role in support of the DIA's internal Officer of Security (SEC). Among other things, his duties included "enabling user activity monitoring on individuals with access to DIA systems, including individuals who are under investigation" and "assisting external partners, such as law enforcement, on the use of insider threat tools." “I am willing to share classified information that I have access to, which are completed intelligence products, some unprocessed intelligence, and other assorted classified documentation,” the email stated. The email included a picture of his government ID used to enter and exit his Washington, D.C. workplace, with name and image redacted, and a username associated with an encrypted messaging platform the recipient could use to continue the conversation. Soon after Laatsch’s email was intercepted, the FBI instigated an undercover operation to trick the IT bod into thinking that he was talking to a genuine spy. The feds’ efforts were not immediately successful. Agents replied on March 23, saying: “Good afternoon, I received your message and share your concerns. We are glad you reached out. I look forward to your response and learning more about your work.” Laatsch did not respond until April 14, after the FBI sent a follow-up via the original email address on April 4. Following additional conversations, in which Laatsch described what information he was offering to the "foreign spy," on April 28, 205, Laatsch entered his office and within 20 minutes began accessing classified information. Prosecutors said he spent much of the entire workday writing on a physical notepad while intermittently looking at his computer monitor, hiding the notebook when coworkers walked by. “The defendant wrote multiple pages of notes, which he then removed from the notepad at his desk and folded into squares,” court documents state. “At the end of his workday, the defendant bent under his desk, placed the folded papers into his socks, and departed the office.” Laatsch repeated the same behavior on April 29, and again on April 30, only this time placing the paper squares in the bottom of his lunchbox. The next day, the IT specialist followed FBI instructions on where to dead-drop the thumb drive - onto which he had transposed state secrets - in an Arlington, Virginia park. Although he believed he was leaving the device for a foreign spy to collect, the FBI instead gathered Laatsch’s deposit and found nine typed documents, eight of which contained information classified as top-secret and contained sensitive compartmented information. Court documents confirmed that the nature of the files Laatsch transmitted included sensitive methods of intelligence collection, intelligence related to foreign military exercises, and analysis of the impact of those military exercises. These were chosen entirely by Laatsch, who had not received a brief on what files to collect from the FBI. In exchanged messages, Laatsch stated he chose the files based on assumed interests. The device also contained a note from Laatsch personally. In it, he said he hoped the initial tranche of files would serve as proof of the type of information to which he had access. Laatsch, whom prosecutors described as an individual who had become disenfranchised with the current administration, also expressed his willingness to accept citizenship in the foreign nation. Further, he said he was “not opposed to other compensation,” but was not in need of financial or other kinds of material rewards. In the interim, Laatsch messaged the "spy" with additional details about how internal investigations are carried out at the DIA, the common “stupid mistakes” made by those under investigation, and that they “should not be too difficult” for him to avoid. The undercover FBI agent arranged a second intel drop for the following month, to which Laatsch agreed. According to the plea agreement, between May 15 and May 27, Laatsch would enter his workplace, log into his classified system, and spend most of the day transcribing classified information by hand into a notebook. He repeatedly folded up the pages and placed them in his socks before leaving at the end of the workday. The FBI arranged the second intel drop for May 29, 2025. It instructed Laatsch to instead head to a specific picnic table in the same Arlington park and electronically transfer the files from his personal computer while situated at the picnic table. Laatsch agreed, executed the transfer to the FBI-controlled address while sitting in the park, and was arrested on the spot. The man waived his right to an attorney and admitted to the offenses when questioned by FBI agents. “By his own admission, Laatsch betrayed his oath by offering classified information to a foreign government, the very thing he was supposed to prevent as an employee of DIA’s Insider Threat Division,” said Roman Rozhavsky, assistant director at the FBI’s Counterintelligence and Espionage Division. “Those entrusted with our nation’s most sensitive information must not exploit their access for personal gain - in this case offering to sell American secrets to buy foreign citizenship. The FBI and our partners will continue to hold accountable all those who betray the trust of the American people.” Laatsch’s plea agreement [PDF] recommends a sentence between 11 and 18 years, including time served, although the court is able to issue a maximum sentence that includes a life term and a $250,000 fine. ®
CISA is still crying out for software vendors to adopt Secure by Design (SBD) development practices, and says in its latest review that longstanding vulnerability classes are still the most exploited. The agency examined soft spots across 2024 and 2025, finding that the majority of those that receive CVEs and make it to the Known Exploited Vulnerability (KEV) catalog belong to decades-old flaws that should have been addressed by now. Injection-related vulnerabilities, such as cross-site scripting (XSS) (CWE-79), OS command injections (CWE-78), and SQL injections (CWE-89) were among the most common across both CVE and KEV records in 2024-2025, CISA said. These were joined by bugs introduced by vendors that didn’t properly mitigate against improper input validation (CWE-20) in their code – the single most-common weakness type across the KEV catalog and registered CVEs. “Threat actors continue to succeed, in part, because simple, preventable software weaknesses remain unaddressed,” CISA said in the review. “Resolving fundamental issues would eliminate a significant portion of today’s most common compromises.” Readers may remember two MITRE reports that have been frequently referred to and revisited since being published years ago. Findings from a 2007 edition examining what the organization called “unforgivable vulnerabilities,” and another in 2023 referring to “stubborn weaknesses,” continue to crop up regularly in modern data. CISA said that in 2024, seven of the 10 most frequent CWEs seen on the CVE list belong to MITRE’s “stubborn weaknesses.” Equally, seven of the 10 most frequent CWEs seen on the KEV catalog, comprising 41.5 percent of all bugs on that list, were also stubborn weaknesses. And three of the top five KEVs also stemmed from unfixed holes, a finding that CISA said demonstrates “how reliably these weaknesses translate into real-world exploitation.” For reference, these three were improper input validation (CWE-20), path traversal (CWE-22), and OS command injections (CWE-78). The data from 2025 follows a similar pattern, CISA said: seven of the top 10 CWES were still those considered “unforgivable” in 2007. “Three of today’s top 10 CWEs would have been considered ‘unforgivable’ nearly two decades ago,” it said. “Their persistence today illustrates that the problem is not technical complexity: it is organizational culture, developer workflows, and systemic gaps in Secure by Design adoption.” For those who can’t remember the paper published 19 years ago, unforgivable vulnerabilities are those that exist because of common, well-documented mistakes, have an “obvious” attack path, the exploit is simple, and attackers can locate the bug in minutes. The same findings can be found in CISA’s Risk and Vulnerability Assessments (RVAs), the no-cost penetration tests the agency carries out on real organizations to improve their security and gain a richer understanding of the broader US cyber landscape. The assessments across both 2024 showed that memory safety and improper input validation vulnerabilities are the most reliable paths to exploitation, accounting for 16.7 percent of KEV entries in 2025. Injection vulnerabilities are also commonly seen in registered CVEs, although these are less commonly exploited in the real-world, especially against cyber-mature organizations. To tackle this pervasive issue, CISA is once again recommending organizations adopt SBD practices, eliminating the stubborn vulnerability classes that continue to support cyberattacks, decades after they were deemed too much of a lingering threat. It ultimately comes down to vendors helping defenders to shoulder less of the security burden. Instead of releasing patch packages that continue to swell to record sizes, just build the software responsibly in the first place. In CISA’s view, this means “owning security outcomes” for customers, killing off the so-called stubborn and unforgivable weaknesses, and improving the automation of configurations, monitoring, and updates. Software buyers should only choose vendors that meet these requirements, and ensure they have software bills of materials (SBOMs) in place to track supply chain risk. “Organizations must shift from reacting to threat actors to fixing the fundamental flaws those actors are known to exploit,” said CISA. “Stronger cybersecurity begins with software that is secure by design. “It requires prioritization of vulnerabilities and collaboration across industry and government. Finally, it demands leadership attention to understand cyber risk as a business risk, a national security threat, and an impediment to operational resilience.” ®
OpenAI has gathered more than 100 of the world's biggest tech and infosec companies to warn that cyber defense is in trouble - a reassuring development given quite a few of them helped build the technology involved. The open letter has more than 100 names attached to it, including many of the companies with the most to gain – or lose – from what happens next. OpenAI, Anthropic, Google and Microsoft are among the AI builders warning about increasingly capable AI attacks, while security heavyweights including Cloudflare, CrowdStrike, Fortinet, and Palo Alto Networks have also signed on. AWS, IBM, Oracle and Cisco are there too, alongside banks, consultancies and other companies whose businesses depend on keeping an increasingly messy technology stack running. Together, they have reached a troubling conclusion: the current approach to cybersecurity isn't working. "We have a limited window to strengthen cyber defenses," the letter warns, predicting that AI-enabled attacks will become "far more widespread and sophisticated" in the coming months as models become more capable. Hospitals, water treatment plants and internet infrastructure are singled out as being at risk. It's an interesting warning given who's making it. Some of the signatories are racing to build ever more capable AI systems, while others make billions selling the cloud services, enterprise software and security tools that are supposed to keep attackers at bay. Still, the underlying problem is real enough. The letter points to old vulnerabilities, unpatched software, misconfigurations and weak authentication as problems that have been piling up for years, particularly across critical infrastructure where security teams are often short on money and staff. Their proposed solution is, inevitably, more AI. The letter calls for cyber-capable models to be put into the hands of more defenders, with cheaper models handling security work at scale and frontier systems reserved for harder problems. Security vendors should continuously test their defenses against frontier AI capabilities, share threat intelligence and help critical infrastructure operators deploy AI-powered defenses. Governments, meanwhile, are asked to fund cybersecurity for essential services, expand trusted-access programs and give hospitals, water utilities and local governments access to capable defensive AI. Companies developing frontier models have their own homework assignment. They should provide "responsible model access, significant funding, training, and hands-on support," particularly to under-resourced critical infrastructure operators, while investing in testing, vulnerability disclosure and tools that make AI agents traceable. What the letter doesn't include is any figure for that "significant funding," or any deadlines or firm commitments from the companies signing it. For now, they're being asked to bring the "full weight of their technology, resources, and expertise" to the problem. It's quite a message from a group that includes some of the biggest names in cloud, enterprise software, and cybersecurity. When more than 100 companies agree that "status quo security won't be enough," it's worth remembering that many of them have been selling that status quo for years. There is some urgency behind all this. AI agents have already been shown finding and exploiting vulnerabilities on their own, while AI-generated exploit code has started turning up in attacks against critical infrastructure. As the models improve, the fear is that those capabilities become cheaper and available to a lot more attackers. That's the "defenders' window" the signatories want to seize: use AI to shore up defenses before the offensive side gets much easier. So, after years of selling organizations cloud services, security software and, more recently, AI, the industry has settled on a fix for the looming AI security problem: better cybersecurity, more resources and more AI. Who will pay for it remains rather less clear. ®
Nothing smarts like a paper cut, but being attacked after leaving an application’s web interface exposed to the internet might be just as painful. Such attacks are the risk to which users of PaperCut print management software find themselves exposed today, after the company revealed a university’s security teams alerted it to an attack. The company analyzed info provided by the university and found a vulnerability in its PaperCut NG and PaperCut MF products, which manage access to printers, track use, and enable printing from myriad client devices. “We are aware of confirmed customer incidents and are treating this matter with the highest priority,” states an urgent security advisory issued on Thursday. Unusually, the advisory is silent on the nature of the flaw and the risk it poses. It looks like the web interface to the company’s products enables access deeper into a user’s networks, because among the indicators of compromise are altered log files, plus alerts from intrusion detection software, endpoint security tools, and network monitoring packages. The company has cooked up an emergency patch but warns it is not an official release. “We have not gone through our usual release process,” states an FAQ. “This is an emergency patch for customers with public-facing PaperCut servers who are unable to take other mitigating action.” Thankfully, those other actions aren’t hard to take: users need to get their PaperCut servers’ web interfaces off the public internet, by allowing access only from trusted internal IP addresses. Fashioning a potent and rapid response to a zero-day attack is never easy. Communicating the nature of the problem can be even harder, as discussing the nature of a flaw invites more attackers to take a shot at a stricken product. PaperCut says it’s working on a better fix and will advise users once it lands. For now, the company is asking customers to apply its wonky patch or take their servers offline ASAP. The Register fancies most users will go for the latter fix, as aside from the issue of finding a change window in which to apply a patch, running unvalidated emergency software is not an appetizing approach. ®