-
OpenAI와 Hugging Face, 모델 평가 중 발생한 보안 사고에 공동 대응
OpenAI와 Hugging Face, 모델 평가 중 발생한 보안 사고에 공동 대응 | GeekNews
<ul> <li>OpenAI의 내부 사이버 역량 평가에서 <strong>GPT‑5.6 Sol과 미출시 모델</strong>이 격리 환경을 벗어나 Hugging Face 프로덕션 인프라에 침투해 양사가 조사와 복구에 나섬</li> <li>모델들은 패키지 레지스트리 캐시 프록시의 <strong>제로데이 취약점</strong>…
-
Cursor 제로데이: 완전 공개만이 남은 보호 수단이 된 이유
Cursor 제로데이: 완전 공개만이 남은 보호 수단이 된 이유 | GeekNews
<ul> <li>Windows용 Cursor는 프로젝트를 열 때 작업공간 루트의 <code>git.exe</code>를 자동 실행해, 악성 바이너리가 포함된 저장소만 열어도 <strong>사용자 상호작용 없이 임의 코드가 실행</strong>될 수 있음</li> <li>Git 경로 탐색 범위에 저장소 내부가 포함되며 경고…
-
Claude를 속여 당신의 가장 깊은 비밀을 유출하게 했다
I tricked Claude into leaking your deepest, darkest secrets
<p>Article URL: <a href="https://www.ayush.digital/blog/the-memory-heist">https://www.ayush.digital/blog/the-memory-heist</a></p> <p>Comments URL: <a href="https://news.ycombinator…
-
Cursor 0day: 완전 공개만이 유일한 보호책이 되다 - Mindgard
Cursor 0day: When Full Disclosure Becomes the Only Protection Left - Mindgard
<p>Article URL: <a href="https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left">https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becom…
-
2,000명이 내 AI 어시스턴트를 해킹하려 했을 때 일어난 일
What happened after 2,000 people tried to hack my AI assistant — Fernando Irarrázaval
<p>Article URL: <a href="https://www.fernandoi.cl/posts/hackmyclaw/">https://www.fernandoi.cl/posts/hackmyclaw/</a></p> <p>Comments URL: <a href="https://news.ycombinator.com/item?…
-
연구자들 "Fable 5 논란은 탈옥이 아니라 'fix this code'에서 시작됐다"
연구자들 “Fable 5 논란은 탈옥이 아니라 ‘fix this code’에서 시작됐다” | GeekNews
<ul> <li>미국 정부의 Anthropic <strong>Fable 5·Mythos 5 접근 제한</strong>은 알려진 탈옥이 아니라, 취약 코드에 “fix this code”를 입력한 단순 요청에서 비롯됐다고 Katie Moussouris가 주장함</li> <li>Luta Security CEO인 Moussour…