Researchers identified an exploit chain dubbed "Claudy Day" affecting Claude.ai that chains three vulnerabilities: invisible prompt injection via URL parameters, an open redirect on claude.com, and data exfiltration via the Anthropic Files API.
These hidden prompts can include attacker-controlled API keys that allow the system to package sensitive user conversation history and upload it to an attacker-controlled Anthropic account via the Files API , without requiring external tools or additional integrations.
Yes. Anthropic has fixed the prompt injection vulnerability and is mitigating the remaining structural issues. Yet, organizations must proactively audit their connected agent integrations.
In a standard, out-of-the-box session, the AI agent can access conversation history and memory, which may include sensitive user information. If a user enables enterprise integrations, specialized tools, or Model Context Protocol (MCP) servers, the potential blast radius expands exponentially.
Threat actors can command the compromised agent to read internal files, interact with connected application programming interfaces, and transmit messages autonomously. Organizations should:
“ Security leaders have a responsibility to prevent their AI assistants from being ‘socially engineered’ into disclosing sensitive or protected information or granting access ,” said Andrew Bolster, Senior R&D Manager at Black Duck.
Saumitra Das, Vice President of Engineering at Qualys, highlighted that the prompt itself is now an attack surface, adding that developers and users are increasingly " dangerously skipping permission checks " to avoid interrupting the agent.
Last month, Claude Code critical flaws allowed RCE and API token theft. PromptArmor in January disclosed an Anthropic Cowork AI vulnerability that allowed file exfiltration via prompt injection without additional user approval, and in July 2025, a critical remote code execution vulnerability was found in the Anthropic MCP Inspector .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
