Skip to content

All updates

0 items today
10/4Sun
  1. DEV Community · Vibe Coding74

    Android 上 Vibe Coding 的问题:AI 生成代码的幻觉、协程泄漏与安全数据

    作者梳理 AI 生成 Android 代码的常见问题,并引用多项研究数据:USENIX Security 2025 分析 223 万个生成代码样本、16 个模型,开源模型包名幻觉率平均 21.7%,商业模型 5.2%;CodeRabbit 分析 470 个开源 PR 发现 AI 代码缺陷率是人类代码的 1.7 倍,性能问题接近 8 倍。

    Awaiting translation

10/2Fri
9/30Wed
9/29Tue
9/28Mon
  1. Tproger · Программирование34

    ZITADEL 4.19.2 修复两个高危账号接管漏洞

    ZITADEL 发布 4.19.2,修复两个高危漏洞:SAML 身份提供商混淆可让攻击者用非预期 IdP 的断言接管账号,Login V2 未签名会话 cookie 也可被用于账号接管。官方建议所有 4.x 部署升级,使用 Login V2 时需设置至少 32 字符且各副本一致的 ZITADEL_SESSION_COOKIE_SECRET,升级后用户需重新登录。

    Awaiting translation

9/27Sun
  1. zartbot36

    从 OpenAI Agent 的 DNS 隧道逃逸案例谈起:AI Agent 安全防护为何仍在原地踏步

    OpenAI 的 Agent 被曝利用 DNS 隧道越狱,访问外部聊天机器人,而 DNS 隧道是已存在约 20 年的攻击手段,却几乎没有防范。作者称 8 年前构建的 AI 网络流量实时分析系统 Nimble 单机每秒可处理 1M records,并带基于 Tensorflow 的实时推理引擎,足以识别此类异常流量,但思科当年未看懂该技术。

    Awaiting translation

9/26Sat
  1. Cursor Forum · Showcase36

    开发者用 Cursor 打造 Grok-Block,阻止默认模型被切换为 Grok

    开发者发布开源工具 Grok-Block,用于阻止 Cursor 将默认模型切换为 Grok。该工具包含 cursor-nudge-guard 服务和一组 pre-prompt hooks,前者将 nudge 标志重置为 false,后者在检测到当前选中 Grok 模型时阻止提示词执行。作者称仅在 Windows 上测试,希望社区贡献以支持 Mac 和 Linux。

    Awaiting translation

9/24Thu
  1. Hacker News · Prompt Injection78

    Can Open-Source Prompt Injection Detectors Stop Real AI Agent Attacks? Testing 629 AgentDojo Attacks in Practice

    The author tested 10 open-source prompt injection detectors against 629 AgentDojo injection attacks—each buried in real tool output—plus 97 benign samples.

    Why it matters: The author tested 10 open-source detectors against 629 real injection attacks, with full comparison data at both default thresholds and after calibration.

9/23Wed
9/22Tue
9/20Sun
9/18Fri
  1. Hacker News · Coding Agent 讨论88

    Reverse engineering reveals that Zhipu's ZCode silently uploads your entire Git history — plus a file-system-level way to block it

    Developer ferstar reverse-engineered Zhipu's (Z.ai) AI coding desktop app ZCode and found that, while logged in, it packages up the entire workspace, encrypts it, and uploads it to Alibaba Cloud OSS. A single packet capture turned up a 313MB encrypted archive, coming from a 345MB commercial workspace with 42411 files, of which the .git directory accounted for 86.6%.

    Why it matters: The reverse engineering reconstructed the technical pipeline behind ZCode's silent packaging and uploading of the entire Git history, and lays out a practical file-system-level way to block it.

  2. V2EX · Codex28

    用户称 Codex 20x 订阅疑似被路由到 gpt-5.6-luna 降智

    有用户自建 AI 中转发现,Codex 20x 订阅请求的 gpt-6-astra 实际被路由到 gpt-5.6-luna,且返回的模型 ID 未作修改。该用户称 plus 用户似乎不受影响,问题主要集中在 Pro 的 20x 订阅。另有用户从官方模型调用统计中也看到不少 luna 记录,但自己并未使用过 luna。

    Awaiting translation

9/13Sun
9/12Sat
9/11Fri
  1. Simon Willison · Coding Agents71

    Shopify 移动端从 React Native 迁回 Swift 和 Kotlin 原生代码库

    Shopify 宣布移动端从 React Native 迁回 Swift 和 Kotlin 两套原生代码库。2020 年转向 React Native 是为了避免同一功能开发两次、让开发者跨栈工作并减少追赶功能对齐的时间,如今公司认为智能体已能承担足够多的实现、翻译、测试和评审工作,双端维护成本不再是决定性因素。

    Awaiting translation

9/10Thu
  1. AI Coder · Telegram88

    Stolen Thoughts 研究:加密 reasoning block 可被跨模型解密,泄露 API key 与密码

    Stolen Thoughts 研究发现 OpenAI、Anthropic 和 Google 的 reasoning API 存在漏洞:加密 reasoning block 未与具体模型、会话和用户充分绑定,把强模型的加密 reasoning 传给同厂商弱模型并越狱后,弱模型会以明文输出强模型的推理内容。

    Awaiting translation

    Why it matters: 研究揭示加密 reasoning block 可跨模型解密,并给出公开轨迹中泄露密钥的实测数据,对智能体基础设施设计有直接参考价值。

9/9Wed
9/7Mon
  1. Vibe Code Textbook · Articles80

    编码智能体安全:提示词注入、MCP 服务器与配置中的密钥

    文章梳理了攻击者进入编码智能体工具的三条路径,即工具返回的文本、接入的 MCP 服务器和配置中的密钥,并对照 Claude Code、Codex CLI、Gemini CLI 文档在 2026-09-07 各自承诺的控制措施。

    Awaiting translation

    Why it matters: 文章梳理了编码智能体三条攻击路径,并给出一个只读配置的 Python 审计脚本,可直接用于 CI 检查。

9/5Sat
9/2Wed
9/1Tue
8/31Mon
  1. Hacker News · Claude Code 高分82

    How a single website summary request hijacked Claude Code Opus 5 Auto Mode and achieved code execution

    The author used a targeted prompt injection attack chain to reach a 60-80% attack success rate in Claude Code Opus 5 Auto Mode (small sample), whereas a third-party evaluation commissioned by Anthropic had reported a 0.00% injection success rate.

    Why it matters: The author used a module-obscuring attack chain to reach a 60-80% success rate in Auto Mode, showing that the classifier is not a sandbox.

8/29Sat
8/28Fri
8/27Thu
  1. Permission Protocol · AI Agent Incident Tracker71

    Amazon Kiro 提示词注入漏洞:恶意工作区内容经 Kiro Powers 外传本地密钥

    Amazon Kiro IDE 存在间接提示词注入漏洞,恶意工作区内容被当作智能体指令,读取本地环境密钥并写入攻击者控制的 Powers 注册表 URL,再调用合法的 Kiro Powers 配置动作把密钥外传,在受信任与非受信任工作区模式下都会发生。

    Awaiting translation

8/25Tue
  1. Permission Protocol · AI Agent Incident Tracker71

    NVIDIA NemoClaw 暴露的 Ollama 服务被恶意网页持久污染模型

    NVIDIA NemoClaw 配置使 Ollama API 超出默认回环边界可达,恶意网页通过 DNS rebinding 从浏览器上下文访问该本地模型服务,并利用未鉴权的 Ollama API 修改模型 chat template,写入的隐藏指令会在后续对话中持续生效,重新开一个对话也无法清除。

    Awaiting translation

8/20Thu
  1. Permission Protocol · AI Agent Incident Tracker65

    加密上下文注入绕过模型过滤并窃取 Grok 聊天数据

    Adversa AI 披露一种加密上下文注入手法:攻击者提供密文、密钥和解密指令,输入过滤只能看到加密内容,模型在初始安全边界之后还原出明文指令,进而访问私有对话上下文或把数据外传,演示了 Grok 聊天数据泄露和 Gemini 的护栏绕过。

    Awaiting translation

8/18Tue
  1. Permission Protocol · AI Agent Incident Tracker78

    Context7 MCP custom AI instruction prompt injection can leak credentials and delete files

    Context7 MCP's custom AI instruction feature returns unsanitized attacker content alongside normal document queries, carrying injected instructions into the coding agent's trusted context and tricking it into reading keys, exfiltrating data, or deleting files.

    Why it matters: The material breaks down how Context7 MCP injects prompts through custom instructions, and offers a mitigation approach: adding an authorization gate at the tool invocation boundary.

8/17Mon