Kryptovalutaticker:
sysadmin från Cyber Security News

AI Double Agent Attack Turns Claude Desktop to Execute Remote Code on a Target Machine

Guru Baran
Jul 8, 2026 at 14:33
27 Visningar
0 Kommentarer
AI Double Agent Attack Turns Claude Desktop to Execute Remote Code on a Target Machine

A compromised email inbox can be weaponized into full remote code execution on a victim’s machine, not through malware or phishing links, but by turning the victim’s own Claude Desktop assistant against them. The attack uncovered by Security researchers at Pentera Labs began with access to a third-party platform that aggregates customer email inboxes, gained through an exploited authentication flow. Rather than pursuing conventional password-reset or phishing routes, the team used inbox access to move laterally into the victim’s Claude account and identified the “Personal Preferences” field, a user-editable prompt that syncs across every device and session tied to the account, as the ideal attack...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!