
Coding-Agent Tunnel Traffic Can Look Almost Identical to Command-and-Control Check-Ins
Coding agents such as Claude Code and Cursor are trusted, vendor-signed tools that developers use to open shells, edit files, call APIs, and install project helpers. That trust creates a difficult detection problem: activity launched below an approved coding agent can still resemble high-severity command-and-control (C2) behavior. Elastic Security telemetry from a macOS developer endpoint […]
The post Coding-Agent Tunnel Traffic Can Look Almost Identical to Command-and-Control Check-Ins appeared first on Cyber Security News.