Tech Times on MSN
Summarizing website in Claude code auto mode can compromise your machine; no fix planned
Claude Code Auto Mode security exploit: Johann Rehberger's Python module-shadowing attack achieves remote code execution ...
A researcher tricked Claude Code into running attacker code up to 80% of the time. Anthropic says the behaviour is working as ...
ИБ-исследователь Иоганн Ребергер (Johann Rehberger) продемонстрировал атаку на Claude Code, работающий с моделью Opus 5 в ...
研究员 Johann Rehberger(网名 wunderwuzzi)近日披露,Anthropic 最新编码代理 Claude Code Opus 5 在默认开启的“自动模式”(Auto Mode)下存在严重安全隐患。测试显示,攻击者可通过看似无害的网页提示,诱导模型在用户机器上下载并执行恶意代码。攻击链复盘:从“总结网站”到任意代码执行Rehberger 向 Claude Code 发出简单指 ...
TechZeitGeist Deutschland (Deutsch) on MSN
Eine Webseiten-Zusammenfassung lenkte Claude Code bis zur Codeausführung
Eine Webseiten-Zusammenfassung führte Claude Code in einem PoC bis zur kontrollierten Codeausführung. Entscheidend sind ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
只是請AI摘要一個網頁,竟可能讓攻擊者在電腦執行惡意程式!資安研究員Johann Rehberger近日展示一套針對Claude Code的攻擊手法,利用藏在惡意網站及壓縮檔中的指令,誘導AI自行下載檔案、撰寫解碼程式,最後觸發攻擊者預先埋設的惡意程式碼。 這項測試鎖定搭載Opus ...
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim ...
חוקר האבטחה יוהאן רהברגר חשף שאפשר להשתלט על Claude Code של Anthropic באמצעות פרומפט פשוט לסיכום של אתר. החוקר הדגים כיצד אתר ...
Rehberger氏はこの攻撃手法をアンソロピックに報告したものの、返答は「当該の挙動は設計どおりに動作している」というもので、対策が必要な問題点ではなく「参考情報」として処理されたという。同社の見解では、Auto ...
O Claude Code, ferramenta de programação baseada em inteligência artificial da Anthropic, pode ser induzido a executar código ...
AI coding agents are increasingly able to browse websites, download files, write programs and execute commands with limited ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results