💥 Did you know that your agents can modify their own traces?
In our new paper, we show that Claude Code, Codex, Antigravity, Open Code, and Grok Build (but not Muse Code!) allow agents to easily modify or even delete their traces, without triggering any guardrails.
Modification and deletion can be done both by misaligned models or external attackers via prompt injections. We draw attention to this issue and suggest that traces should be much better protected than they are now!
安全研究者 Johann Rehberger 公开了对 Microsoft SQL Server Management Studio 中 AI 数据库助手 SQL Copilot 的研究,发现其中存在严重的提权路径,可从 SELECT 权限提升至 SYSADMIN。作者提醒用户确保 SSMS 安装已更新,并感谢 Microsoft 快速修补该问题,该研究还在两周前的 BlueHat Asia 上进行了展示。作者提到数据库 CONSTITUTION.md 这一概念,完整技术细节与视频演示见其博客文章。
面向 Claude Fable 5 的领域专属智能体红队测试!!
很快将登上排行榜:https://decodingtrust-agent.com/
引用Zhaorun Chen@zrrrr_cn
🚨 Claude Fable 5 JAILBROKEN.
We ran a quick security scan of Claude Fable 5 with Claude Code on our DecodingTrust-Agent Platform (https://decodingtrust-agent.com) and obtained 15%+ ASR with several high-severity failures😱🚨
Most concerningly, we found that Fable 5 appears very aggressive in financial-risk scenarios, sometimes directly executing transactions initiated from indirect prompt injections, without even confirming with the user!
Top 3 most severe attack trajectories we observed👇
CSA《Top Threats to Cloud Computing 2026》报告把 AI 相关风险拆成两个独立类别:AI 增强型攻击(第 2 位)与 AI 系统攻陷(第 6 位)。前者指攻击者用 AI 加速侦察、漏洞利用、深度伪造钓鱼和生成多态恶意软件,把传统攻击压缩到机器速度;后者指模型、提示词、训练数据、连接工具与编排逻辑本身被提示注入、数据投毒、对抗输入或模型窃取等手段操纵,且可能无需完全攻破主机环境。报告认为云安全与 AI 安全的边界正在消失,但两类威胁不可互换,否则会留下盲区。
Coalition for Secure AI(CoSAI)Workstream 2 发布 AI Shared Responsibility Framework(AI SRF),用一个五层模型覆盖完整 AI 堆栈并为每一组件指定唯一的责任方,试图终结 AI 出事后的相互推诿。该框架将 AI 业务与合规义务、训练数据与影子 AI、应用开发者的输入校验与访问控制、托管与服务模型的云及 MLOps 平台、以及基础模型供应链分别划归不同角色负责,其中模型提供方需对提示注入易感性、训练数据溯源和漏洞披露流程担责。Air Canada 客服聊天机器人误告丧亲票价被判赔偿、汽车经销商聊天机器人被骗以一美元售车两案说明问责缺口并非理论问题,而是 AI 部署速度超过治理能力的现实写照。
微软发布第三份年度《负责任 AI 透明度报告》,围绕自适应治理与技术风险管理、实用工具与能力、共享实践与合作伙伴关系三个方向调整其负责任 AI 项目。报告称已重构 Responsible AI Standard,按模型、平台服务、应用等技术栈组件分层设定要求,并对具备最强网络能力的 AI 系统施加最严格的风险管理措施。微软还推出 AI Red Teaming Agent、Agent evaluators、RAMPART、ASSERT 与 Agent Control Specification 等工具,用于智能体系统的评估、运行时控制和行为监控,并称其为少数在广泛产品组合上通过 ISO 42001 认证的公司之一。