AI Coding Agents Are Tripping Security Alarms Written to Catch Human Intruders
Claude Code, Cursor and OpenAI Codex are setting off endpoint-detection rules built for attackers — decrypting browser credentials, touching Windows credential stores and writing to startup folders in the ordinary course of doing their jobs — forcing security teams to decide what a “normal” developer machine even looks like now.