,

China raises alarm over potential “security loophole” in Anthropic’s AI coding software.

Beijing – On Wednesday, a regulatory body in China issued a warning regarding a potential “security backdoor” found in the coding tool Claude Code, developed by the U.S.-based AI firm Anthropic.

The National Vulnerability Database (NVDB), which focuses on cybersecurity and operates under the Ministry of Industry and Information Technology, reported that this backdoor could allow the software to send sensitive data, such as user locations and personal identification details, back to Anthropic’s servers without user consent.

Claude Code is an AI-powered coding assistant capable of generating, debugging, and reviewing computer code based on user input.

Although Anthropic restricts access to its products for users and entities in China and other nations it considers hostile, individuals can still utilize these tools within China via VPNs or third-party proxy services.

The NVDB stated on its website that it recently identified significant security risks associated with Claude Code, labeling it a “severe threat.”

As of now, Anthropic has not issued any comments to AFP regarding these allegations, which first surfaced in specialized technology publications last week.

In light of these findings, the NVDB recommended that institutions and users conduct thorough checks promptly and either uninstall the software or update to the latest secure version that does not include the problematic backdoor code. It also emphasized the need for organizations to bolster network traffic monitoring to avert unauthorized data leaks.

According to insiders, Chinese tech company Alibaba informed its employees last week that the use of Claude Code would be prohibited starting July 10 due to security apprehensions.

Previously, Anthropic accused Alibaba of reverse-engineering its artificial intelligence models to replicate their functionalities, a practice known as “distillation.”

Responding to claims that Claude Code was collecting data from Chinese users, engineer Thariq Shihipar posted on X last week, stating, “This is an experiment we launched in March aimed at preventing account misuse by unauthorized resellers and protecting against distillation.” He noted that the team had implemented stronger protective measures since then and had intended to remove this feature for some time, with plans for a complete rollback in the upcoming release.


Discover more from News Dive

Subscribe to get the latest posts sent to your email.


AI Search


NewsDive-Search

🌍 Detecting your location…

Select a Newspaper

Breaking News Latest Business Economy Political Sports Entertainment International

Search Results

Searching for news and generating AI summary…

Top Categories

Latest News


Sri Lanka


Australia


India


United Kingdom


USA


Sports