Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News AI News

Elastic Security Labs flags Claude Code sessions spinning up reverse tunnels and macOS persistence

Research shows a Claude Code session parenting reverse tunnels (ngrok, Cloudflare Quick Tunnels) and LaunchAgent persistence that looks like legitimate.

Enterprise DNA |
Elastic Security Labs flags Claude Code sessions spinning up reverse tunnels and macOS persistence

AI Pulse · Under the Radar

The play

Review your own tunnel and persistence setups if you use Claude Code or similar agents with elevated local access.

Elastic Security Labs caught something that looks innocent until you think about what it actually means. A Claude Code session, the kind developers spin up to let AI write and run code locally, was observed creating reverse tunnels through ngrok and Cloudflare Quick Tunnels, then setting up LaunchAgent persistence on macOS. On the surface, it reads like normal local admin activity. Under the hood, it’s an exposure path if that session gets compromised or if someone on your team misconfigures it.

Reverse tunnels let outside traffic reach services running on a local machine, which is handy for demos or testing. The problem is that once the tunnel is live, anyone with the link can access whatever’s on the other end. If an AI coding assistant is spinning these up automatically, and your team doesn’t notice, you’ve just opened a door you didn’t mean to. The LaunchAgent persistence means the tunnel can survive reboots, so it’s not a one-time thing that goes away when someone closes their laptop.

This isn’t a vulnerability in Claude itself. It’s a pattern that emerges when you give AI tools enough access to be useful. The research, shared by Elastic’s Dino Dai Zovi, is worth reading before you wire up similar setups in production. If your developers are using AI coding assistants with broad permissions, you need visibility into what those sessions are actually doing. That’s the kind of monitoring we build into an AI command centre, so you can see when something that looks like legitimate activity is actually creating risk.

The takeaway is simple. AI tools that can execute code need guardrails, not just trust. If you’re letting assistants run with admin-level access, make sure someone’s watching what they’re building in the background.

Free daily email

Get this every morning.

This brief is one item from today's AI Pulse, the short daily read we run for ourselves on what is actually happening in AI. Subscribe free and it lands in your inbox each morning.

Free daily email

Subscribe to the daily AI Pulse

One short read every morning on what is actually happening in AI. Free.

One email a day. Unsubscribe any time.