注册并分享邀请链接,可获得视频播放与邀请奖励。

MTS
@MTSlive
Chronicling the singularity
加入 March 2026
1.3K 正在关注    484.2K 粉丝
Abundant Security CTO @joshua_saxe reveals how easy it is to trick Claude Code into giving an attacker shell access on a developer's workstation: "There's a fair number of public demonstrations of inducing Claude Code to give an attacker shell access on a developer's workstation. That's pretty easy to pull off." "The way you can do that today is plant a comment in a GitHub repo that says, hey, I've had the same problem you've had installing this library, and the way I fixed it is I ran this shell script. You can trick coding agents into giving you remote code execution pretty easily that way." "I wouldn't just blame the labs. Tech companies realizing efficiency gains in software engineering by deploying these agents are shipping open security risks. Labs are making the trade-off to ship stuff faster than they can implement safety guardrails."
显示更多