DAILY WORKFLOW ARCHIVE

2026-09-03 AI 与数据工作流雷达

候选线索仅供信息发现,请在引用或实践前回到原始来源核验。

2026-09-03 AI 与数据工作流雷达

来源:The Hacker News。这里只保留与 AI 编程、数据/研究工作流、安全边界或可信工程直接相关的高信号线索;不抓取全文,也不代表事实核验或产品推荐。

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

主题:AI 编程与开发工具
来源日期:2026-09-02
相关性分数:4
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a command that the agent runs on the developer’s machine, four of them still unpatched at publication. The command executes as the user, outside the agent’s sandbox and without an approval prompt, and exploitation requires the repository to arrive as files with its .git directory intact, which a shared archive, a shared drive, a sync folder, or a USB stick preserves, whereas an ordinary clone does not. Fixes have shipped for goose, Claude Code, and Cursor, while Hermes Agent, Qwen Code, Grok Build, and a second path in Claude Code were still executing repository-supplied commands when Manifold retested them on September 1. OpenAI published three CVEs of its own the same day covering the identical class in Codex, credited to three unrelated research groups. “The helper runs outside Codex’s command sandbox and wi…

可转化方向:评估是否能转化为临床编程、代码审查、测试或自动化实践

前往 The Hacker News 阅读原文


Shadow AI Agents Are Multiplying. Here’s How to Find and Secure Them

主题:AI 与数据安全
来源日期:未提供
相关性分数:3
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。

Learn how eight common discovery approaches work, what they find, and what they don’t.

可转化方向:评估 AI 辅助研究和编程中的隐私、凭据、供应链与安全边界

前往 The Hacker News 阅读原文


Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

主题:AI 工程与可信性
来源日期:2026-09-02
相关性分数:2
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。

Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program . “The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them build better defenses, before new threats arrive,” Google said . “So defenders have an early advantage, to help them protect vital infrastructure – which in turn protects people who rely on those systems.” The tech giant said it’s currently working with over 650 partners globally, including CrowdStrike, Datadog, Menlo Security, Palo Alto Networks, and Snowflake. The program is available to a group of Google Cloud customers, government agencies, and cybersecurity partners. The release of Gemini 3.8 Flash Cyber comes a little over a month after Google unveiled Gemini 3….

可转化方向:关注模型评估、可信 AI、监控与工程治理对实际 AI 工作流的启发

前往 The Hacker News 阅读原文