DAILY WORKFLOW ARCHIVE

2026-09-02 AI 与数据工作流雷达

候选线索仅供信息发现,请在引用或实践前回到原始来源核验。

2026-09-02 AI 与数据工作流雷达

来源:The Hacker News。这里只保留与 AI 编程、数据/研究工作流、安全边界或可信工程直接相关的高信号线索;不抓取全文,也不代表事实核验或产品推荐。

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

主题:数据工作流与自动化 / AI 工程与可信性
来源日期:2026-09-01
相关性分数:7
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。

METR (short for Model Evaluation and Threat Research and pronounced “Meter”), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered “two notable security incidents” where external actors attempted to gain unauthorized access to its systems. No sensitive information is believed to have been accessed as a result of these incidents, it said, adding that a version of its findings was shared with AI companies it works with prior to public disclosure. The attacks have not been attributed to any known threat actor or group, nor did they involve AI agents breaking into its evaluations. “In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits,” METR said . “In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful at…

可转化方向:评估对可复现分析、依赖管理、数据质量或研究工程流程的启发;关注模型评估、可信 AI、监控与工程治理对实际 AI 工作流的启发

前往 The Hacker News 阅读原文


Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

主题:AI 编程与开发工具
来源日期:2026-08-31
相关性分数:4
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。

Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX’s artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security . The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its toolkit, shell history, and encryptor. CloudSEK said the exposed open directory leaked “months of activity” that was active against more than 20 organizations across nine countries between April and July 2026. Four of those victims have since been listed on its data leak site. “The operator used Cursor, an agentic coding assistant, to plan attacks in Russian, while excluding CIS [Commonwealth of Independent States] ranges and CIS-country domains, without exception,” CloudSEK noted. Details about Aurora first emerged in late May 2026, with CYFIRMA highlighting atta…

可转化方向:评估是否能转化为临床编程、代码审查、测试或自动化实践

前往 The Hacker News 阅读原文


Shadow AI Agents Are Multiplying. Here’s How to Find and Secure Them

主题:AI 与数据安全
来源日期:未提供
相关性分数:3
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。

Learn how eight common discovery approaches work, what they find, and what they don’t.

可转化方向:评估 AI 辅助研究和编程中的隐私、凭据、供应链与安全边界

前往 The Hacker News 阅读原文


Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

主题:AI 与数据安全
来源日期:2026-09-01
相关性分数:3
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka KindaRails2Shell (CVSS score: 9.5) - A vulnerability that could allow an unauthenticated attacker to read arbitrary files from the server, leak Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens, ultimately leading to remote code execution. Attackers can exploit CVE-2026-66066 by uploading a crafted image by taking advantage of the discrepancy between Active Storage and libvips in how they read input files. Successful exploitation requires affected applications to use libvips for Active Storage …

可转化方向:评估 AI 辅助研究和编程中的隐私、凭据、供应链与安全边界

前往 The Hacker News 阅读原文


Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance

主题:AI 与数据安全
来源日期:2026-08-31
相关性分数:3
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。

Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot tell you whether an agent’s access is legitimate. AI has moved from the browser tab to the endpoint with harnesses like Claude Code. They run on developers’ machines, execute bash commands locally, and connect to third parties via MCP servers, skills, and plugins. All this so the user can outsource labor to the machine and focus on designing, thinking, and creating. Local agents are not a niche category. They account for 68.6% of the AI agents Token Security discovers in customer environments, and they often inherit the employee’s credentials, network position, and permissions. The shift to the endpoint has major implications for security. With Claude Code, there is no ce…

可转化方向:评估 AI 辅助研究和编程中的隐私、凭据、供应链与安全边界

前往 The Hacker News 阅读原文