惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
罗磊的独立博客
爱范儿
爱范儿
Apple Machine Learning Research
Apple Machine Learning Research
S
Schneier on Security
V
Vulnerabilities – Threatpost
T
Tenable Blog
博客园 - 【当耐特】
博客园 - 聂微东
I
Intezer
S
Securelist
C
Cisco Blogs
腾讯CDC
T
The Exploit Database - CXSecurity.com
NISL@THU
NISL@THU
P
Proofpoint News Feed
Cyberwarzone
Cyberwarzone
Security Archives - TechRepublic
Security Archives - TechRepublic
D
Darknet – Hacking Tools, Hacker News & Cyber Security
美团技术团队
P
Proofpoint News Feed
M
MIT News - Artificial intelligence
AWS News Blog
AWS News Blog
A
About on SuperTechFans
Last Week in AI
Last Week in AI
Cloudbric
Cloudbric
S
Secure Thoughts
PCI Perspectives
PCI Perspectives
The Last Watchdog
The Last Watchdog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
B
Blog RSS Feed
Recorded Future
Recorded Future
大猫的无限游戏
大猫的无限游戏
C
CERT Recently Published Vulnerability Notes
酷 壳 – CoolShell
酷 壳 – CoolShell
G
Google Developers Blog
The Register - Security
The Register - Security
博客园 - 叶小钗
博客园 - 司徒正美
博客园_首页
Google DeepMind News
Google DeepMind News
Hacker News: Ask HN
Hacker News: Ask HN
Spread Privacy
Spread Privacy
雷峰网
雷峰网
I
InfoQ
The Hacker News
The Hacker News
T
Threat Research - Cisco Blogs
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Schneier on Security
Schneier on Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

The Register - Software: AI + ML

Anthropic, now atop the AI bubble, files for its IPO Sick and wrong: Ontario auditors find doctors' AI note takers routinely blow basic facts OpenAI exec says it will burn $50B on compute this year Astera speaks softly and carries a big switch Anthropic unleashes finance agents for Claude IBM asks DBAs to trust AI to act on their behalf ServiceNow adds agent kill switches to AI control tower British mathematician hands OpenClaw agent a credit card Microsoft fixes VS Code after Copilot credited human code Shadow IT has given way to shadow AI. Enter AI-BOMs AI inference just plays by different rules How TeamViewer ONE transforms IT operations from firefighting to autopilot How TeamViewer ONE transforms IT operations firefighting aut Inference is giving AI chip startups a 2nd chance to shine How to roll your own local AI coding agents CIOs will be the governors for AI agents Govern your bots carefully or chaos could ensue Mozilla pushes back against Google's Prompt API SAP user group slams 'uncertainty' in ERP giant's API policy Microsoft boss tells investors the company is working to 'win back fans' Anthropic tops OpenAI in LLM revenue stakes Amazon's chips become a $20B business Fooling large language models just keeps getting simpler Amazon tells its engineers to review all AI output ZTE powers 2026 Jiangsu Football League with 5G-A & AI robot Future holiday horror: ‘A robot lost my luggage in Tokyo’ The future of software development has less development OpenAI jumps out of Microsoft's bed, into Amazon's Bedrock Vintage chatbot lives in the past like an elderly relative IBM's AI coding 'partner' Bob hits general availability Locked, stocked, and losing budget: AI vendor lock-in bites Ex-AWS legend explains what enterprises need to make AI work DeepSeek's new models offer big inference cost savings Anthropic admits it dumbed down Claude with 'úpgrades' Microsoft gives your Word documents an AI co-author you didn’t ask for Datadog digs down into GPU efficiency as AI costs soar Robotic arm powered by AI bats away ping-pong challenge Partnerships drive ZTE’s strategy to unlock AI potential Gov.uk says AI gaslighting Brits with stale Gov.uk data Google says it has all the answers for AI agent sprawl NeuBird plans a bright future for incident response NeuBird AI plans a bright future for incident response AI-assisted intruders pwned Vercel via OAuth abuse and a pilfered employee account Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus Schmoozebots: study finds flattery will get AI everywhere New Android development tool designed for robots, not humans AI is reshaping Britain's datacenter map away from London Just like phishing for gullible humans, prompt injecting AIs is here to stay Anthropic debuts Claude Design, because who needs designers? Mozilla takes on enterprise AI providers with Thunderbolt Anthropic ejects bundled tokens from enterprise seat deal Maine to pause big bit barns as local opposition spreads If you want into Anthropic's Claude club, you may have to show ID Nobody knows how many CVEs Anthropic's Project Glasswing has actually found Allbirds shoe company moving to AI infra is the top Bad teacher bots can leave hidden marks on model students Networks not ready for the challenges of AI traffic US states can't account for datacenter tax breaks. Literally Salesforce debuts Headless 360 agentic platform Waymo's self-driving cars face their toughest test yet: London Commvault has a Ctrl+Z for rogue AI agents Nvidia slaps forehead: AI, that's what quantum needs! OpenAI CEO Sam Altman home attack suspect charged Anthropic: Claude quota drain not caused by cache tweaks AI vs the cold hard reality of the legal profession China wants AI to prepare school lessons and mark homework Linux 7.0 debuts as Linus Torvalds ponders AI's impact Anthropic's Mythos has The Kettle crew curious, skeptical I vibe coded web app: It was enlightening and uncomfortable The AI divide putting open weights models in spotlight Amazon rejects AWS climate disclosure proposal UK to spend £15M on AI mapping in knife crime crackdown UK to spend £15M on AI-powered crime mapping in knife violence crackdown Rebrand automation as 'zero-token architecture' to master AI Call your existing automation ‘zero-token architecture’ to become an instant agentic AI wiz Only 28% of AI infrastructure projects fully pay off UALink delivers 2.0 spec before v. 1.0 silicon ships Only 28% of AI infrastructure projects fully pay off, survey finds No-Nvidia interconnect club delivers 2.0 spec before v1.0 silicon ships Anthropic reveals $30bn run rate and plans to use 3.5GW of new Google AI chips AI slop got better, so now maintainers have more work AMD's AI director slams Claude Code for becoming dumber and lazier since last update Anthropic closes door on subscription use of OpenClaw AI will make anyone a 10x programmer, but with 10x the cleanup PrismML debuts energy-sipping 1-bit LLM in bid to free AI from the cloud Netflix – yes, Netflix – jumps on the AI bandwagon with video editor AI models will deceive you to save their own kind Google battles Chinese open-weights models with Gemma 4 Microsoft shivs OpenAI with three new AI models for speech and images They thought they were downloading Claude Code source. They got a nasty dose of malware instead Even Microsoft knows Copilot shouldn't be trusted with anything important Google's TurboQuant saves memory, but won't save us from DRAM-pricing hell Claude Code bypasses safety rule if given too many commands OpenAI gets $122B to 'just build things' as the world blows them up One in seven Americans are ready for an AI boss, but they might not trust it Claude Code source leak reveals how much info Anthropic can hoover up about you and your system Oracle cuts jobs across sales, engineering, security Anthropic goes nude, exposes Claude Code source by accident GitHub backs down, kills Copilot pull-request ads after backlash Microsoft Fabric Database Hub only a 'partial' solution for admins
Git identity spoof fools Claude into giving bad code the nod
Carly Page Carly Page · 2026-04-16 · via The Register - Software: AI + ML

AI + ML

Forged metadata made AI reviewer treat hostile changes as though they came from known maintainer

Security boffins say Anthropic's Claude can be tricked into approving malicious code with just two Git commands by spoofing a trusted developer's identity.

In a blog published this week, Manifold Security showed how an AI-powered code reviewer built on Claude accepted changes that appeared to come from a legitimate maintainer. By setting a fake author name and email in Git, the team made a commit appear to originate from a trusted source, then passed it through an automated review flow where the model approved it.

This is not a Git vulnerability – commit metadata has always been relatively easy to fake unless additional controls like signing are enforced. The problem arises when that metadata is treated as a signal of trust. In this case, the model appeared to give weight to the author's claimed identity rather than independently assessing whether the change itself was sound.

In Manifold's test, the workflow was set to auto-approve pull requests from "recognized industry legends," so the trust rule was obvious. In the real world, it's usually less explicit – checks against org membership, past contributions, or a maintainer list – but it's the same problem underneath. None of that proves who actually made the change.

"The motivation behind such configurations is understandable. Maintainers of popular open source projects are drowning in PRs," Manifold said. "Automating review for contributions from known, trusted figures reduces the bottleneck. But it creates an assumption that authorship can be trusted at face value."

Manifold compares the setup to the recent OpenClaw Cline package compromise, where a poisoned package slipped into a trusted environment and was treated as legitimate long enough to cause damage. In both cases, something that appeared to come from a reliable source was given a level of trust it hadn't earned.

What changes with systems like Claude is how that trust is applied. A human reviewer might question why a particular maintainer is making an unexpected change or take a closer look at the diff. An automated reviewer is more likely to follow its internal signals consistently, and if those signals include author identity, spoofing that identity becomes a way in.

"Open source libraries are increasingly relying on AI-powered workflow tools to auto-review and approve pull requests, yet these agents are easily fooled, creating opportunities for threat actors to bypass security controls and poison popular code repositories," Manifold warned.

Manifold's takeaway is that the guardrails can't live in the model. If nothing else is checking who did what, bad code won't just be suggested – it'll get pushed. ®