惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
N
Netflix TechBlog - Medium
P
Proofpoint News Feed
D
Docker
J
Java Code Geeks
L
LangChain Blog
Microsoft Security Blog
Microsoft Security Blog
The GitHub Blog
The GitHub Blog
I
InfoQ
Stack Overflow Blog
Stack Overflow Blog
云风的 BLOG
云风的 BLOG
Engineering at Meta
Engineering at Meta
MongoDB | Blog
MongoDB | Blog
月光博客
月光博客
T
Tailwind CSS Blog
M
MIT News - Artificial intelligence
Blog — PlanetScale
Blog — PlanetScale
Google DeepMind News
Google DeepMind News
腾讯CDC
罗磊的独立博客
U
Unit 42
爱范儿
爱范儿
Vercel News
Vercel News
MyScale Blog
MyScale Blog

Futurism

Sam Altman Now Trying to Gain Control of Electric Grid Top Chinese Court Issues Sweeping Legal Crackdown on AI Deepfakes Meta Releases Uber-Creepy AI Chatbot as Its Platforms Crumble Under Grotesque Child Abuse LG TVs Caught Secretly Recording Users and Scanning Their Homes For Other Devices, Even When Disconnected From the Internet People Are Telling Their Darkest Thoughts to AI Without Realizing They Can Easily Become Public Hackers Are Selling Stolen Scans of 153 Million US and Canadian Drivers Licenses, Which Very Likely Include Yours FBI Now Allowing History of Bestiality Among New Recruits The Transcripts of OpenAI Models Plotting Together to Commit an Actual Crime Is Pretty Chilling Flock Is Quietly Selling Powerful Drones That Scan License Plates From the Sky McDonald's Has Hundreds of Pages of Intel on Its Repeat Customers, and You Can Get a Copy of Yours Man Wearing Pervert Glasses Films Himself Harassing Famous Female Comedian in the Middle of TV Shoot Sensing He's in Deep Trouble, Flock Safety CEO Says It's All Been a Big Misunderstanding Hackers Created a Device That Can Take Over a Boeing 737 Jet's Autopilot Without Anyone Noticing Man Covers Car in Special Wrap That Breaks Flock Cameras' Electronic Brains Scammers Tremble as AI Comes for Their Jobs Why Aren't Any AI Companies Watching Their Frontier Models to Make Sure They Don't Go on Hacking Sprees? Jealously Watching OpenAI and Anthropic, Meta Suddenly Claims That Its AI Went on a Hacking Spree Too OpenAI's Escaped Models Were Allegedly Rampaging More Extensively Than Previously Reported This New Meta "Advertisement" Is Absolutely Brutal Suspicion Grows About OpenAI's Tale About Its Rogue Hacker AI OpenAI Says a Group of Its Models Broke Out of Secure Containment and Hacked a Prominent AI Site It's Laughably Easy to Poison Open-Weight AI Models, Researcher Finds AI Browsers Can Basically Be Hypnotized Into Turning Against Their User and Carrying Out Devastating Hacks Meta’s AI Support Bot Is Giving Hackers Access to Other People’s Instagram Accounts Just by Asking Websites Are Spying on Your Solid State Drive The MyPillow Guy’s Entire Business is Being Held Hostage by Hackers Riot Games Denies Using Anti-Cheat Software That Bricks Hackers’ Computers The Trump Phone Appears to Have Already Leaked Its Customers’ Personal Information Through a Glaring Exploit College Kid Shuts Down High Speed Trains With a Laptop and a Radio Google Alarmed by Formidable AI-Powered Zero-Day Cyberattack
If You AI-Generate Code, Hackers Just Found a Devious Met...
Joe Wilkins · 2026-07-29 · via Futurism

A white humanoid robot with red markings on its head and neck stands out sharply in focus among a crowd of blurred, dark-colored humanoid figures.

evgeniy jamart / Shutterstock

Sign up to see the future, today

Can’t-miss innovations from the bleeding edge of science and tech

Despite certain improvements in accuracy, large language models still hallucinate a lot. So much so, in fact, that cybersecurity researchers warn that criminals can easily weaponize delusional AI outputs to spread malware throughout the internet.

According to SecurityWeek, the attack works by exploiting a persistent flaw in AI coding assistants. Basically, when these tools recommend third-party software packages, there’s a strong possibility that they include names of ones that don’t actually exist.

Astonishingly, cybersecurity researchers at Tel Aviv University and Intuit found that this scenario can be exploited in common AI coding tools ranging from Cursor to Microsoft’s Copilot, at rates of anywhere form 85 to 100 percent, depending on the specifics of the engineering task.

The attack, called “adversarial hallucination squatting,” or “hallusquatting,” takes advantage of this fact. To run it, attackers can simply identify hallucinated package names that they know AI coding assistants will reference, register them as real repositories, and stuff malware inside. That malicious package then lies in wait for the near-guarantee than an AI assistant will access it and clone it into its owner’s machine.

Because the attack relies on an automated process, a victim likely won’t even know their AI assistant downloaded the malware until well after it begins executing code.

And because the compromise is a feature of the technology itself, a massive array of AI assistants are vulnerable, including Cursor, OpenClaw, Gemini, GitHub Copilot, and many more.

The researchers claim they notified AI companies about the exploit and held back some sensitive details that would help attackers improve their workflows, but the underlying problem remains: AI assistants are remarkably confident liars — and apparently easy marks for the next generation of cyber criminals.

More on AI: A Whole Bunch of People’s Claude Chats Are Publicly Accessible Online, and There’s Some Wildly Private Stuff in There