玩 Vibe Coding 的朋友,特别划重点注意下这个,恶意代码喜欢藏的位置:
Claude Code hijack (~/.claude/settings.json): A SessionStart hook is injected into Claude Code's settings file.
VS Code task injection (.vscode/tasks.json): A folderOpentask trigger is written to workspace task configurations.
供应链攻击太多了,多到发麻,愿你的设备不是肉鸡。
Composer 2.5 is now available inside Grok Build.
Composer 2.5 is a fast, highly intelligent model that excels on long-running tasks and following complex instructions.
大裁员后的翻车来了。这几天,Meta 旗下的 Instagram,被曝 AI 助手出现史诗级漏洞,导致多个 Ins 博主账号被盗。
平台给 AI 助手,默认开了一个超级权限,可以在无任何验证的情况下,直接帮人修改 Ins 的绑定邮箱。
流程则是
1. 用 VPN 假装自己在目标账号的国家
2. 跑到 Meta AI 聊天里,说我是这个账号的主人,想换个新邮箱
3. AI 傻乎乎地相信了,发验证码给黑客的新邮箱
4. 黑客把验证码告诉 AI,AI 就直接把账号邮箱,换成黑客的了,然后黑客就能重置密码、抢走账号
目前,Meta 已紧急修补了这个巨大漏洞。
In collaboration with @nvidia, we’re open-sourcing a dataset of security scans for 67,453 ClawHub skills on @huggingface:
- NVIDIA SkillSpector flagged 1/2 for agentic risk
- Only 0.31% were malicious
- No two scanners agreed on more than 8.5% of risks
https://t.co/ml624ExiLG