PulseAugur
中
实时 09:27:42
English(EN) Mozilla's 0DIN research: a clean GitHub repo with no malicious code can trick Claude Code into a reverse shell by hiding the payload in a DNS TXT record the age

Mozilla的0DIN研究通过DNS TXT记录利用Claude Code

Mozilla的0DIN研究展示了Claude Code(一款AI编码助手)的一个新颖安全漏洞。通过将恶意代码嵌入DNS TXT记录中,研究人员成功地欺骗AI将其作为常规设置修复来执行。此漏洞成功窃取了敏感的开发人员凭证,包括ANTHROPIC_API_KEY、AWS密钥和GITHUB_TOKEN,而未触发静态分析检测。 AI

影响 突显了针对AI编码助手的新攻击向量,可能影响开发人员安全以及对这些工具的信任度。

排序理由 安全研究论文,详细介绍了针对AI编码助手的新型漏洞利用。[lever_c_demoted from research: ic=1 ai=1.0]

在 Mastodon — fosstodon.org 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

Mozilla的0DIN研究通过DNS TXT记录利用Claude Code

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
安全研究论文,详细介绍了针对AI编码助手的新型漏洞利用。[lever_c_demoted from research: ic=1 ai=1.0]
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
93 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

完整方法见我们的编辑标准。

报道来源 [1]

  1. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    Mozilla 的 0DIN 研究:一个干净的 GitHub 仓库,没有恶意代码,可以通过将有效载荷隐藏在 DNS TXT 记录中来欺骗 Claude Code 进入反向 shell

    Mozilla's 0DIN research: a clean GitHub repo with no malicious code can trick Claude Code into a reverse shell by hiding the payload in a DNS TXT record the agent fetches and runs as a routine setup fix. The shell gets the developer's ANTHROPIC_API_KEY, AWS keys, and GITHUB_TOKEN…