Mindgard 在 Amazon Kiro IDE 中发现一条数据外泄路径:攻击者控制的仓库内容被当作指令,诱导 Agent 读取本地敏感信息并写入 IDE 配置,最终由 IDE 自动发起网络请求把数据带出。测试针对 Windows 上的 Kiro IDE 0.7.45,在受信任与不受信任工作区中均复现。利用需要两步用户操作,即通过 File → Open Workspace From File 打开恶意工作区文件,然后向 Agent 发送任意消息,之后流程无需用户再要求 Kiro 访问或传输敏感数据,因此利用难度被评为低。Amazon 通过 HackerOne 验证了报告,并在 Kiro IDE 0.8.140 中修复;该提交获 40 美元 Amazon 商店礼品卡,CVE 资格仍在评估。
💥New Paper!
The HF investigation found agents trying to tamper with their transcripts. Apparently they failed in their attempts, but ~10% of traces are missing...
We show that almost all public agents like Codex and Claude Code can easily tamper with their own traces.
💥 Did you know that your agents can modify their own traces?
In our new paper, we show that Claude Code, Codex, Antigravity, Open Code, and Grok Build (but not Muse Code!) allow agents to easily modify or even delete their traces, without triggering any guardrails.
Modification and deletion can be done both by misaligned models or external attackers via prompt injections. We draw attention to this issue and suggest that traces should be much better protected than they are now!
面向 Claude Fable 5 的领域专属智能体红队测试!!
很快将登上排行榜:https://decodingtrust-agent.com/
引用Zhaorun Chen@zrrrr_cn
🚨 Claude Fable 5 JAILBROKEN.
We ran a quick security scan of Claude Fable 5 with Claude Code on our DecodingTrust-Agent Platform (https://decodingtrust-agent.com) and obtained 15%+ ASR with several high-severity failures😱🚨
Most concerningly, we found that Fable 5 appears very aggressive in financial-risk scenarios, sometimes directly executing transactions initiated from indirect prompt injections, without even confirming with the user!
Top 3 most severe attack trajectories we observed👇