A compromised email inbox can be weaponized into full remote code execution on a victim’s machine, not through malware or phishing links, but by turning the victim’s own Claude Desktop assistant against them. The attack uncovered by Security researchers at Pentera Labs began with access to a third-party platform that aggregates customer email inboxes, gained through an exploited authentication flow. Rather than pursuing conventional password-reset or phishing routes, the team used inbox access to move laterally into the victim’s Claude account and identified the “Personal Preferences” field, a user-editable prompt that syncs across every device and session tied to the account, as the ideal attack...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!