Claude Code 2.1.268 patches silent deny-rule bypasses and MCP secret leakage
Claude Code 2.1.268 fixes silent security boundary failures via symlinks and shell commands, plus stops MCP configs leaking secrets in plaintext.
Topic
16 posts about Security from Simon Carter.
Claude Code 2.1.268 fixes silent security boundary failures via symlinks and shell commands, plus stops MCP configs leaking secrets in plaintext.
From 8 September 2026, Gemini Enterprise admins can apply CAA policies to restrict who authenticates into Gemini based on device, location, and more.
Claude Enterprise admins can now enable automatic security scanning for third-party skills and plugins, catching malicious content at upload or edit.
OpenAI's GA Secure MCP Tunnel uses an outbound-only tunnel-client daemon so private MCP servers can serve ChatGPT, Codex, and the Responses API with no inbound firewall rules.
A missing noindex tag meant shared Claude chats were publicly discoverable on Google, exposing legal advice, API keys, and crypto wallet credentials.
Anthropic's Compliance API now connects Claude Enterprise to 28 security platforms including Palo Alto Networks, Rubrik, Okta, and Sumo Logic.
Claude Code's latest release adds parameter-level permission syntax, proximity-based .claude/ directory resolution, and pre-launch safety screening for sub-agents.
Two back-to-back Copilot CLI releases fix a dangerous agentStop infinite-loop bug, tighten macOS sandbox defaults, and patch Anthropic subagent reliability.
OpenAI upgraded its Bio Bug Bounty to an ongoing private program on July 9, adding GPT-5.6 to scope and doubling the reward to $50,000.
Claude Code versions 2.1.91–2.1.196 contained an undisclosed monitoring mechanism. Here's what it did, who's affected, and what to do now.
Anthropic's vault-stored environment variables let Claude Managed Agents authenticate CLI tools without the API key ever entering the agent's context window.
Anthropic's public beta adds cron-based scheduling and a network-boundary credential vault to Claude Managed Agents, removing two common DIY infrastructure headaches.
OpenAI's Lockdown Mode, a security setting that blocks live web access and agentic features to defend against prompt injection, is now available to all personal ChatGPT plans.
The latest Codex CLI update adds session archiving, OSC 8 hyperlinks in TUI markdown, richer MCP status, and short-lived WebSocket tokens for remote control.
Anthropic's Frontier Red Team mapped 13,873 real attacks to MITRE ATT&CK — and found the framework has no ID for the autonomous agentic behavior defining the highest-risk actors.
Codex CLI 0.137.0 closes three command-safety gaps and adds an alpha Windows elevated sandbox provisioning path for admins.