Tego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions

https://hackernoon.imgix.net/images/zrmhiGUO5YO0UGWoKCzGMHKsbc63-5383geb.jpeg

Tel Aviv, Israel, July 14th, 2026/CyberNewswire/--Tego AI, a cybersecurity company, published new research identifying a potentially critical security weakness in Claude Tag, Anthropic’s native integration between Claude and Slack.

Researchers observed Claude Tag responding to messages containing the literal text “@Claude” without requiring a genuine structural Slack mention. As a result, content delivered through bots, webhooks, automated feeds, or other external sources could potentially be interpreted as instructions.

The research demonstrated the potential impact through a connected internal organizational resource. Bot-generated messages instructed Claude Tag to retrieve internal information, publish it into Slack, and subsequently delete the original resource using the organization’s configured connection.

The video below demonstrates the observed behavior and its potential impact on connected organizational systems.

“Our research raises a fundamental question for every organization deploying enterprise AI agents: who is actually authorized to instruct the agent?” said Tal Melamed, CTO and Co-Founder of Tego...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more