Six popular AI code assistants (Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, Windsurf) can execute code undetected on developer systems through symlink exploits in attack scenarios known as GhostApproval.
The Claude apps gateway replaces individual credentials per developer with a centralized access point featuring identity, policy, telemetry, routing, and spend-cap functions.
AI agents with self-execution privileges become an attack vector in the software supply chain when they install tampered packages without human approval.
Anthropic is making Claude Code and Claude Cowork available to US government agencies through a FedRAMP-High-certified desktop application to support software modernization and administrative tasks.
Model selection determines the available intelligence, while effort level controls how intensively Claude works—such as how many files are read, tests executed, and steps processed.
Vera automates security testing for autonomous AI agents through a three-stage process of risk discovery, combinatorial generation, and evidence-based verification, uncovering critical security flaws in production agent frameworks.
Alberta reviewed 466 million lines of government code in 20 hours using Claude and fixed vulnerabilities that would have taken conventional methods 6.5 years to address.
Claude Sonnet 5 with 1M token context becomes the default model in Claude Code 2.1.197 and costs $2 per 1M input tokens and $10 per 1M output tokens during the promotional phase.