PulseAugur
中
实时 21:28:26
English(EN) One Argument-Injection Bug Took Down OpenAI Codex at Pwn2Own. Here's the Detection Gap.

AI 代理 OpenAI Codex 在 Pwn2Own 上被参数注入攻破

在 Pwn2Own 爱尔兰 2026 上,研究人员成功利用了 OpenAI Codex(一个基于云的 AI 编码代理)中一种新颖的参数注入漏洞。该漏洞通过针对传递给代理工具的参数,而不是模型本身的推理,绕过了传统的提示注入防御。该漏洞凸显了当前 AI 安全的一个关键差距,因为许多工具专注于入站提示过滤,而未能检查 AI 代理与其执行环境之间交换的数据。 AI

影响 凸显了一类针对代理工具执行的新型 AI 安全漏洞,可能需要超越提示过滤的新防御机制。

排序理由 安全工具 Sentinel 的博客文章详细介绍了在 Pwn2Own 上发现的 OpenAI Codex 漏洞,重点关注该工具的安全能力。

在 dev.to — LLM tag 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

AI 代理 OpenAI Codex 在 Pwn2Own 上被参数注入攻破

本文如何被排名

Signal score
6 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
安全工具 Sentinel 的博客文章详细介绍了在 Pwn2Own 上发现的 OpenAI Codex 漏洞,重点关注该工具的安全能力。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Same-day
Cluster formed today. Ranking reflects the current source set at time of score.

完整方法见我们的编辑标准。

报道来源 [1]

  1. dev.to — LLM tag TIER_1 English(EN) · Cor E ·

    一次参数注入漏洞导致 OpenAI Codex 在 Pwn2Own 上崩溃,揭示检测盲点

    <p>Pwn2Own Ireland 2026 wrapped its first day with 32 zero-days popped across smart home hubs, printers, and a handful of AI systems. Researchers walked away with over $388,000. That's a normal Pwn2Own headline. What's not normal is the line buried a few paragraphs in: a single a…