註冊並分享邀請連結,可獲得影片播放與邀請獎勵。

MTS
@MTSlive
Chronicling the singularity
加入 March 2026
1.3K 正在關注    484.2K 粉絲
Abundant Security CTO @joshua_saxe reveals how easy it is to trick Claude Code into giving an attacker shell access on a developer's workstation: "There's a fair number of public demonstrations of inducing Claude Code to give an attacker shell access on a developer's workstation. That's pretty easy to pull off." "The way you can do that today is plant a comment in a GitHub repo that says, hey, I've had the same problem you've had installing this library, and the way I fixed it is I ran this shell script. You can trick coding agents into giving you remote code execution pretty easily that way." "I wouldn't just blame the labs. Tech companies realizing efficiency gains in software engineering by deploying these agents are shipping open security risks. Labs are making the trade-off to ship stuff faster than they can implement safety guardrails."
顯示更多