← العودة للجدول
Hackers Can Hijack Claude Code MCP Traffic to Steal OAuth Tokens
📅 2026-06-08 05:16:32
🟠 High 🔥 No Cyber Security News Exploit AI/LLM

📋 الوصف الكامل

A five-step attack chain that silently redirects Claude Code’s Model Context Protocol (MCP) traffic through attacker-controlled infrastructure, intercepting OAuth bearer tokens that grant persistent, broadly scoped access to connected SaaS platforms like Jira, Confluence, and GitHub with no patch incoming from Anthropic. Researchers at Mitiga Labs have demonstrated the attack, with the entry

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

📡 المصدر

Cyber Security News

✅ الحلول والتخفيف

Apply vendor security patch

🔗 المصدر الأصلي ←