Sunday , September 27 2026
Alibaba

Alibaba Reportedly Bans Claude Code for Suspected AI Tool Backdoor

Alibaba is said to be getting ready to ban the use of Anthropic’s Claude Code in its own systems starting July 10. This choice follows claims that the AI coding helper has a hidden detection method that acts like a backdoor.

The news, first reported by the Chinese financial outlet Yicai and later confirmed by Reuters, has not been officially acknowledged by Alibaba. It shows the rising tensions between big AI companies due to worries about model safety, data theft, and gathering information about rivals.

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Claude Code, Anthropic’s tool for coding, has quickly become popular with business developers. It helps create, fix, and improve code right in terminal settings.

Its increasing presence in businesses makes the supposed security worries very important, especially for big companies like Alibaba that handle large cloud and AI systems.

This ban comes at a time when Anthropic and Alibaba have both made claims against each other about model distillation and taking data without permission.

The controversy began with a June 30 Reddit post by a user named “LegitMichel777,” who claimed to have reverse-engineered Claude Code while trying to restore a disabled remote control feature.

Versions of Claude Code since 2.1.91 (released on April 2) are said to have hidden rules that check system settings, based on technical analysis shared by the user and summarized by many security news sources.

The tool checks if a user’s proxy settings or system timezone match items in two hidden lists linked to Chinese companies and AI research groups, like Alibaba, Baidu, ByteDance, and Moonshot AI.

The system does not send telemetry directly. Instead, it changes detection results by slightly adjusting internal prompts, changing date styles, and swapping punctuation marks.

If validated, this could represent a new form of covert environmental fingerprinting designed to evade traditional detection methods while enabling behavioral tracking or policy enforcement.

Anthropic has not made a public statement about these claims. But, a member of the Claude Code development team said on social media that the feature is meant to stop abuse by finding account reselling and big attempts to copy the model.

The developer indicated that this functionality would be removed in an upcoming release, with reports suggesting remediation efforts were already underway as of July 1. Based on this timeline, the feature may have been active for approximately three months.

In a letter on June 10 to U.S. lawmakers, Anthropic said that groups tied to Alibaba’s Qwen AI created a big scheme with about 25,000 fake accounts, leading to over 28 million interactions with Claude models in six weeks. Alibaba has not said anything publicly about these claims.

Despite many talks, no outside security check has confirmed the claimed backdoor’s presence or purpose. The lack of official comments from both companies leaves big questions unanswered about whether the tool is a security risk, a defensive measure against fraud, or just a misunderstood feature.

If it happens, Alibaba’s ban would be one of the first major rules against suspected hidden features in an AI coding tool. This could change how companies trust AI development tools.

Check Also

AI models

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according …