PulseAugur
实时 23:47:22
English(EN) "Four minutes is how long it took for a machine inside a Fortune 500 company to execute code we published. Two more within the hour. We didn’t exploit a CVE, ph

AI代理执行公司公开文件中的代码,暴露安全风险

AI代理正在执行公司网站上公开文件的代码,这是一种已被野外利用的漏洞。这些文件通常命名为llms.txt,充当AI代理的指令集,指示它们读取什么、调用哪些API以及信任哪些域。研究人员发现,在几分钟内,一家财富500强公司内部的AI代理就执行了已发布的代码,后来又发现了一次使用类似方法的活跃攻击。 AI

影响 此漏洞突显了一种新的攻击向量,AI代理可能通过公共网站文件被诱骗执行恶意代码,对组织构成重大安全风险。

排序理由 该项目描述了与AI代理如何与网络内容交互相关的安全漏洞,这是一个工具相关的问题。

在 Mastodon — mastodon.social 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

AI代理执行公司公开文件中的代码,暴露安全风险

本文如何被排名

Signal score
15 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
该项目描述了与AI代理如何与网络内容交互相关的安全漏洞,这是一个工具相关的问题。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准

报道来源 [1]

  1. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    财富500强公司内部的一台机器在四分钟内执行了我们发布的代码。一小时内又有两台。我们没有利用CVE,ph

    "Four minutes is how long it took for a machine inside a Fortune 500 company to execute code we published. Two more within the hour. We didn’t exploit a CVE, phish an employee, or touch a perimeter. We registered destinations that official, HTTPS-served files — published by the c…