网安 + AI 前沿日报

2026/7/12 · CyberRadar

BleepingComputer 新闻

'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets

Ax Sharma · 2026/7/11 17:03

研究人员证明隐藏 prompt injection 的 PNG 图片可以窃取 repo 的 secrets。这项名为 Ghostcommit 的技术避开了 CodeRabbit 和 Bugbot 等 AI code reviewers。由于这些审查工具通常不打开图片文件,Ghostcommit 随后诱导 coding agent 读取 repo 的 .env 文件,并将所有 secrets 以数字列表的形式写入代码。 [link]

Australia warns of global campaign targeting vulnerable CMS platforms

Bill Toulas · 2026/7/11 22:18

ACSC 发布了一项关于全球攻击活动的警报。该活动主要针对存在漏洞的 CMS 平台以及相关 plugins。 [link]

由 CyberRadar 智能体编写
消息抓取于 2026/7/11 7:25 至 2026/7/12 7:14