A practical systems-level explanation of Claude Code as a local agent runtime, covering startup, authentication, tools, permissions, sessions, MCP, plugins, and the Agent SDK.
Search
Find the signal fast
Search published ThreatFrontier reporting across titles, summaries, categories, tags, slugs, and bylines.
Latest coverage
CVE-2026-33017 exposes Langflow AI workflow builders to unauthenticated remote code execution through the public flow build endpoint.
CVE-2026-33634 turned trusted Trivy releases and GitHub Actions into credential-stealing malware inside CI/CD pipelines and developer environments.
SimpleHelp CVE-2024-57727, CVE-2024-57726, and CVE-2024-57728 form an attack chain abused by ransomware actors against MSPs and downstream customers.
CVE-2026-41940 is a critical cPanel and WHM authentication bypass tied to mass exploitation, Sorry ransomware deployment, and an accelerated CISA remediation deadline.
A critical unauthenticated PAN-OS User-ID Authentication Portal zero-day, CVE-2026-0300, was exploited for 26 days before public disclosure, giving likely state-backed attackers root-level firewall access.