PulseAugur
实时 18:51:00
English(EN) One Malicious Payload Hijacked Claude Code AND Codex Unchanged — The 'Friendly Fire' Exploit Has No…

新的“友军火力”漏洞劫持了多个 AI 编码代理

一种名为“友军火力”(Friendly Fire)的新漏洞揭示了像 Claude CodeOpenAICodex 这样的 AI 编码代理存在严重的安全隐患。AI Now Institute 的研究员 Boyan MilanovHeidy Khlaaf 发现,一个单一的恶意负载可以在不作任何修改的情况下劫持 Claude Sonnet 4.6Claude Sonnet 5Claude Opus 4.8 和运行 GPT-5.5 的 Codex。该漏洞之所以能奏效,是因为这些代理难以区分它们应该分析的代码和恶意指令,导致它们在被要求检查外部代码库时执行有害代码。 AI

影响 该漏洞凸显了 AI 编码代理中存在的根本性安全缺陷,可能导致代码库被大规模泄露,并需要超越模型更新的新的安全范式。

排序理由 在 AI 编码工具中发现安全漏洞。

在 Towards AI 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

新的“友军火力”漏洞劫持了多个 AI 编码代理

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
在 AI 编码工具中发现安全漏洞。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
48 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

完整方法见我们的编辑标准

报道来源 [1]

  1. Towards AI TIER_1 English(EN) · Chew Loong Nian - AI ENGINEER ·

    一个恶意载荷劫持了 Claude 代码,而 Codex 未受影响——“友军火力”漏洞没有…

    <div class="medium-feed-item"><p class="medium-feed-image"><a href="https://pub.towardsai.net/one-malicious-payload-hijacked-claude-code-and-codex-unchanged-the-friendly-fire-exploit-has-no-1c40cc3698cf?source=rss----98111c9905da---4"><img src="https://cdn-images-1.medium.com/max…