---
title: "SecurityBrief: Claude Code flaw leaves deny rules vulnerable in long workflows"
description: Bonfy CEO Gidi Cohen comments on the Claude Code vulnerability in workflows.
---

[In the News ](https://www.bonfy.ai/in-the-news)

# [SecurityBrief: Claude Code flaw leaves deny rules vulnerable in long workflows](https://www.bonfy.ai/in-the-news/securitybrief-claude-code-flaw-leaves-deny-rules-vulnerable-in-long-workflows)

 Written by [Rosa Lear](https://www.bonfy.ai/in-the-news/author/rosa-lear) | Apr 9, 2026 4:25:58 PM

A vulnerability called GrafanaGhost allows attackers to quietly extract sensitive data from Grafana environments without user interaction or traditional compromise techniques.

Discovered by researchers at Noma Security, the [flaw](https://noma.security/blog/grafana-ghost/) highlights how AI-driven features can introduce new, difficult-to-detect attack paths in widely used platforms.

“Treat AI assistants and agents as a new, first-class attack surface. The threat model must explicitly cover indirect prompt injection, tool calling, retrieval behavior, and cross-system data movement — not just model jailbreaks or classic web vulns,” said Gidi Cohen, CEO & Co-founder at Bonfy AI in an email to eSecurityPlanet.

Read the rest of the article here: [https://itbrief.news/story/claude-code-flaw-leaves-deny-rules-vulnerable-in-long-workflows ](https://itbrief.news/story/claude-code-flaw-leaves-deny-rules-vulnerable-in-long-workflows)

[View full post](https://www.bonfy.ai/in-the-news/securitybrief-claude-code-flaw-leaves-deny-rules-vulnerable-in-long-workflows)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Rosa Lear"
  },
  "dateModified" : "2026-04-30T16:42:57.293Z",
  "datePublished" : "2026-04-09T16:25:58Z",
  "headline" : "SecurityBrief: Claude Code flaw leaves deny rules vulnerable in long workflows",
  "image" : {
    "@type" : "ImageObject",
    "height" : 400,
    "url" : "https://48068878.fs1.hubspotusercontent-na1.net/hubfs/48068878/Logo-Bonfy-400x400%20%281%29.png",
    "width" : 400
  },
  "mainEntityOfPage" : "https://www.bonfy.ai/in-the-news/securitybrief-claude-code-flaw-leaves-deny-rules-vulnerable-in-long-workflows",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "In the News"
  }
}
```