AI 编码助手悄然泄露开发密钥,配置文件暗藏敏感凭证
一位安全研究员在审计 npm 包时发现,AI 编码助手 Claude Code 生成的 .claude/ 配置文件被意外打包进发布包,内含实时 API 令牌、环境变量等敏感凭证。Lakera 团队随后对约 46,500 个 npm 包进行扫描,发现 30 个包中的 33 个 .claude/ 文件含有真实密钥,包括 npm 认证令牌、GitHub 个人访问令牌、Telegram 机器人令牌等。进一步研究表明,该问题不限于 npm,在 Python、Java 及容器制品中也出现类似痕迹。此外,作者对大量网站进行 HTTP 扫描,约千分之一网站公开暴露了 .claude/ 文件,内含数据库凭据与内部路径,攻击者可借此横向移动。这一现象被视为生态系统层面的安全问题,根源在于开发者在 AI 会话中对命令选择“始终允许”,导致本地文件被无意随代码一同发布。 #AI安全 #ClaudeCode #凭证泄露 #npm #开发安全 #供应链安全 #配置泄露 #大模型
一位安全研究员在审计 npm 包时发现,AI 编码助手 Claude Code 生成的 .claude/ 配置文件被意外打包进发布包,内含实时 API 令牌、环境变量等敏感凭证。Lakera 团队随后对约 46,500 个 npm 包进行扫描,发现 30 个包中的 33 个 .claude/ 文件含有真实密钥,包括 npm 认证令牌、GitHub 个人访问令牌、Telegram 机器人令牌等。进一步研究表明,该问题不限于 npm,在 Python、Java 及容器制品中也出现类似痕迹。此外,作者对大量网站进行 HTTP 扫描,约千分之一网站公开暴露了 .claude/ 文件,内含数据库凭据与内部路径,攻击者可借此横向移动。这一现象被视为生态系统层面的安全问题,根源在于开发者在 AI 会话中对命令选择“始终允许”,导致本地文件被无意随代码一同发布。 #AI安全 #ClaudeCode #凭证泄露 #npm #开发安全 #供应链安全 #配置泄露 #大模型
微软发现Claude Code漏洞,可窃取GitHub账号凭证
微软威胁情报团队发现,Anthropic旗下Claude Code的GitHub自动化流程存在提示词注入漏洞,攻击者可借此窃取CI/CD工作流中的敏感凭证。研究人员在监测公开代码库时注意到针对AI辅助型GitHub工作流的攻击尝试,随后展开调查。攻击者可将恶意指令隐藏在HTML注释中,在GitHub展示界面不可见,但能被读取原始Markdown源码的AI模型识别。通过提交一条GitHub工单,无需项目修改权限即可操控机器人执行修改操作。微软验证发现,Anthropic此前已为部分工具设置沙箱,但文件读取工具未受同等限制,恶意提示词可绕过防护读取系统文件中的API密钥等凭证。微软于4月29日向Anthropic报告该漏洞,后者在5月5日发布Claude Code 2.1.128版本修复,通过限制对/proc/目录敏感文件的访问来防止凭证泄露。 #AI安全 #提示词注入 #ClaudeCode #Anthropic #微软 #GitHub #凭证泄露 #漏洞 #科技新闻
微软威胁情报团队发现,Anthropic旗下Claude Code的GitHub自动化流程存在提示词注入漏洞,攻击者可借此窃取CI/CD工作流中的敏感凭证。研究人员在监测公开代码库时注意到针对AI辅助型GitHub工作流的攻击尝试,随后展开调查。攻击者可将恶意指令隐藏在HTML注释中,在GitHub展示界面不可见,但能被读取原始Markdown源码的AI模型识别。通过提交一条GitHub工单,无需项目修改权限即可操控机器人执行修改操作。微软验证发现,Anthropic此前已为部分工具设置沙箱,但文件读取工具未受同等限制,恶意提示词可绕过防护读取系统文件中的API密钥等凭证。微软于4月29日向Anthropic报告该漏洞,后者在5月5日发布Claude Code 2.1.128版本修复,通过限制对/proc/目录敏感文件的访问来防止凭证泄露。 #AI安全 #提示词注入 #ClaudeCode #Anthropic #微软 #GitHub #凭证泄露 #漏洞 #科技新闻
Agent评测引入「活的」Benchmark 概念
据新智元报道,Claw-Eval-Live 提出“活的”Benchmark 概念,通过信号采集与任务筛选,确保评测内容始终紧跟企业实际痛点,而非固定不变的题库。该评测不仅关注最终结果,还会追踪执行过程,从数据调用到状态变更,全面验证 Agent 的能力与可靠性。这一创新旨在解决传统静态评测脱离真实应用场景的问题,使评测更贴近实际需求。 #Agent评测 #活的Benchmark #ClawEvalLive #AI #智能体 #动态评测 #企业痛点 #新技术
据新智元报道,Claw-Eval-Live 提出“活的”Benchmark 概念,通过信号采集与任务筛选,确保评测内容始终紧跟企业实际痛点,而非固定不变的题库。该评测不仅关注最终结果,还会追踪执行过程,从数据调用到状态变更,全面验证 Agent 的能力与可靠性。这一创新旨在解决传统静态评测脱离真实应用场景的问题,使评测更贴近实际需求。 #Agent评测 #活的Benchmark #ClawEvalLive #AI #智能体 #动态评测 #企业痛点 #新技术
Brianni AI 发布可验证的运营商盲加密聊天,集成 GPT/Claude/Gemini
一款名为 Brianni 的 AI 聊天应用宣称解决了对话隐私的核心难题:运营者即使有意也无法读取用户聊天内容,且这一承诺可通过公开代码独立验证。该应用整合了 OpenAI GPT、Anthropic Claude 和 Google Gemini 三大模型,所有聊天历史均使用用户设备本地生成的 24 词恢复短语派生的密钥加密,服务器仅存储无法解密的密文。唯一出现明文的环节在 AWS Nitro Enclave 硬件隔离环境中,模型请求处理完毕后立即清除内存,无状态设计确保不残留数据。此外,应用在本地通过正则表达式与 NER 模型对姓名、邮箱等个人可识别信息(PII)进行掩码,再发送至 AI 提供商,额外增加了隐私保护层。开发方指出,传统隐私声明往往不可证伪,而 Brianni 的系统提供了可重现的验证流程,并奖励前五名成功验证者。 #Brianni #AI隐私 #可验证安全 #硬件隔离 #GPT #Claude #Gemini #加密聊天 #隐私技术
一款名为 Brianni 的 AI 聊天应用宣称解决了对话隐私的核心难题:运营者即使有意也无法读取用户聊天内容,且这一承诺可通过公开代码独立验证。该应用整合了 OpenAI GPT、Anthropic Claude 和 Google Gemini 三大模型,所有聊天历史均使用用户设备本地生成的 24 词恢复短语派生的密钥加密,服务器仅存储无法解密的密文。唯一出现明文的环节在 AWS Nitro Enclave 硬件隔离环境中,模型请求处理完毕后立即清除内存,无状态设计确保不残留数据。此外,应用在本地通过正则表达式与 NER 模型对姓名、邮箱等个人可识别信息(PII)进行掩码,再发送至 AI 提供商,额外增加了隐私保护层。开发方指出,传统隐私声明往往不可证伪,而 Brianni 的系统提供了可重现的验证流程,并奖励前五名成功验证者。 #Brianni #AI隐私 #可验证安全 #硬件隔离 #GPT #Claude #Gemini #加密聊天 #隐私技术
三星利润飙升1800%,AI芯片需求推动业绩
据三星电子发布的初步财报指引,由于人工智能(AI)内存芯片的全球需求旺盛,该公司预计第二季度营业利润同比暴增约19倍。三星在4月至6月期间实现营业利润89.4万亿韩元(约合584亿美元),创下连续三个季度历史新高,销售额更是达到171万亿韩元,同比增长逾一倍。半导体供应持续紧张,推动芯片价格上涨,三星作为全球领先的存储芯片制造商,其强劲表现主要得益于AI数据中心对高性能内存的爆发式需求。分析人士指出,AI热潮让内存厂商持续受益,但供应紧张可能延续至明年。尽管三星股价当日小幅回落,但年内市值已翻番,其竞争对手SK海力士涨幅更超过200%。目前三星、SK海力士正与韩国政府共同推进大规模投资计划,以扩大本土芯片产能。 #三星 #AI芯片 #半导体 #利润暴涨 #存储芯片 #科技新闻 #韩国经济
据三星电子发布的初步财报指引,由于人工智能(AI)内存芯片的全球需求旺盛,该公司预计第二季度营业利润同比暴增约19倍。三星在4月至6月期间实现营业利润89.4万亿韩元(约合584亿美元),创下连续三个季度历史新高,销售额更是达到171万亿韩元,同比增长逾一倍。半导体供应持续紧张,推动芯片价格上涨,三星作为全球领先的存储芯片制造商,其强劲表现主要得益于AI数据中心对高性能内存的爆发式需求。分析人士指出,AI热潮让内存厂商持续受益,但供应紧张可能延续至明年。尽管三星股价当日小幅回落,但年内市值已翻番,其竞争对手SK海力士涨幅更超过200%。目前三星、SK海力士正与韩国政府共同推进大规模投资计划,以扩大本土芯片产能。 #三星 #AI芯片 #半导体 #利润暴涨 #存储芯片 #科技新闻 #韩国经济
Thoughts on AI
What is the actual state of AI? I guess, it depends on who you ask. On the one hand, Google (and obviously others) is forcing AI to the absolute limit, replacing the default search behavior because “everyone loves it” , but on the other hand, it seems that everyone actually hates it. And it’s absolutely odd feeling that when I read something on the Internet these days I’m less and less sure that I ready actual human being. That’s why smallweb is so important. Let’s get back to recommendation model (like simple blogroll page) and maybe endorse human validation protocols like . Steam Controller and Steam Machine are finally out, but for some reason I immediately lost my interest… I promised to myself that when the great trio come out, I’ll buy all of them, but now… I don’t know. My current PC is 6 years old now and sometimes it’s hard to play the latest games without
What is the actual state of AI? I guess, it depends on who you ask. On the one hand, Google (and obviously others) is forcing AI to the absolute limit, replacing the default search behavior because “everyone loves it” , but on the other hand, it seems that everyone actually hates it. And it’s absolutely odd feeling that when I read something on the Internet these days I’m less and less sure that I ready actual human being. That’s why smallweb is so important. Let’s get back to recommendation model (like simple blogroll page) and maybe endorse human validation protocols like . Steam Controller and Steam Machine are finally out, but for some reason I immediately lost my interest… I promised to myself that when the great trio come out, I’ll buy all of them, but now… I don’t know. My current PC is 6 years old now and sometimes it’s hard to play the latest games without
sacrificing graphics, but that Steam Machine is (almost) DOA. It’s not overpriced as many say, but in the end, it’s not for me. After I finish Gothic Remake (great game, btw!), I’m going back in time to re-explore Mass Effect trilogy, because I’ve never finished it. No pressure to update my PC then. Don’t know if you scrobble your music on , but I found that I’ve been doing it since 2008, non-stop. Almost 20 years. Amazing! That’s kind of (social media from Web 2.0 era) service that I like. It’s there when you need it, and only then. Glad to see that upcoming macOS is visually improved after this whole Liquid Glass thing, but then still… more AI, AI, AI, AI… CultRepo released The Story of C++ two weeks ago, and it was cool to see Brian Kernighan using his old Intel Macbook Air with a yellow sticky note as camera blocker (adorable). But what’s more, I absolutely love the colors on his screen. There is a thing that most of the Bell Labs alumni still use these colors and I definitely recognize Plan 9 color scheme there. Not sure whether it’s a sentiment or these colors actually improve readability… From my perspective, I found that the older I get, the more I like warmer colors on my screen. Whenever I can I choose beige over white. Regarding programming (or related things), due to the fact that you can’t control these supply chain attacks that happen every other day. I hardened my neovim config (still work in progress, though) to make sure that nothing updates automatically. I just stopped trusting the way things are done these days. Even trustworthy maintainers can be hacked, and that’s not their fault. Things have changed drastically and the dilemma has arisen — is it better to update your software or not , to prevent security issues? Crazy times… The other thing for (neo)vim is that I need to master reading / navigating code with it. I’ve been focusing on writing for the whole time, but just recently — thanks to some blog post I don’t remember right now — learned that vi(m) was created to read code in first place. That will allow me to actually comfortably use neovim at work to navigate through the huge (usually unfamiliar) codebases. My mind is still on pointing my cursor somewhere and click, scroll, click, scroll, repeat…