BTC $63,963.78 -2.28%
ETH $1,854.70 -2.10%
BNB $563.99 -0.87%
XRP $1.08 -2.26%
SOL $73.79 -2.81%
TRX $0.3293 -0.53%
DOGE $0.0693 -0.92%
ADA $0.1616 -3.35%
BCH $211.49 -0.39%
LINK $8.27 -2.89%
HYPE $57.15 -2.52%
AAVE $90.85 -5.44%
SUI $0.7029 -5.54%
XLM $0.1768 -3.95%
ZEC $473.95 -6.78%
BTC $63,963.78 -2.28%
ETH $1,854.70 -2.10%
BNB $563.99 -0.87%
XRP $1.08 -2.26%
SOL $73.79 -2.81%
TRX $0.3293 -0.53%
DOGE $0.0693 -0.92%
ADA $0.1616 -3.35%
BCH $211.49 -0.39%
LINK $8.27 -2.89%
HYPE $57.15 -2.52%
AAVE $90.85 -5.44%
SUI $0.7029 -5.54%
XLM $0.1768 -3.95%
ZEC $473.95 -6.78%

code

All
Article
Flash

Slow Fog Cosine: Claude Code exposes high-risk security vulnerabilities, malicious configuration files may silently execute commands

The founder of Slow Fog, Yu Xian, retweeted a tweet on the X platform regarding the potential poisoning attack risks of Claude Code and published an analysis of the poisoning attack details targeting Grok Build CLI and Claude Code CLI.It pointed out that the security mechanisms of Grok Build CLI are not unified, with different code paths having different trust assumptions, creating gaps that serve as channels for attackers. Attackers may execute arbitrary commands through malicious project configuration files without the user's knowledge, thereby stealing API keys, cloud credentials, or controlling local devices.Researchers constructed a testing environment and found that on Mac systems, if Claude Code is affected, executing specific test commands can trigger the local calculator to launch, proving the existence of potential command execution risks.If the attack is successful, attackers may further steal API keys from AI services like Claude and OpenAI, resulting in account cost losses, gain access to servers and data by obtaining cloud service credentials from AWS, Alibaba Cloud, Tencent Cloud, modify code repositories to implant backdoors, and use local devices as jump points to attack corporate internal networks. It is reported that the related vulnerabilities have existed for a year.

OpenAI has launched the next generation GPT-5.6 series models, currently available only to trusted partners using Codex and the API

According to official news, OpenAI has officially launched the preview version of the next-generation GPT-5.6 series models, including the flagship model Sol, the balanced model Terra, and the fast low-cost model Luna. GPT-5.6 introduces a brand new maximum reasoning effort and features a super strong mode that accelerates complex tasks through sub-agents.The flagship model Sol introduces the Ultra mode, which combines maximum reasoning intensity with sub-agent collaboration. In the Terminal-Bench 2.1 command line workflow test, Sol achieved a score of 88.8%, which increased to 91.9% in Ultra mode, surpassing GPT-5.5's 83.4% and Claude Fable 5's 88.0%. The mid-range model Terra performs close to GPT-5.5 while being priced at half, and the lightest model Luna is designed specifically for everyday automation tasks. Sol is priced at $5 per million input tokens and $30 for output, and it supports reducing secondary call costs by utilizing prompt caching.In terms of security, the security assessment confirmed that Sol did not exceed the critical thresholds of the Preparedness Framework cybersecurity. OpenAI has invested over 700,000 A100 equivalent GPU hours in automated red team exercises, equipping the entire series of models with a defense stack that includes rejection mechanisms, real-time abuse classifiers, and account-level audits. Although the current limited release follows the U.S. government's security framework, OpenAI emphasizes that it does not want a government-led access mechanism to become the long-term default model, as it would limit defenders' access to cutting-edge tools.
app_icon
ChainCatcher Building the Web3 world with innovations.