Complex Mathematics

Claude can be tricked into sending your private company data to hackers – all it takes is some kind words



  • Claude’s Code Interpreter can be exploited to exfiltrate private user data via prompt injection
  • Researcher tricked Claude into uploading sandboxed data to his Anthropic account using API access
  • Anthropic now treats such vulnerabilities as reportable and urges users to monitor or disable access

Claude one of the more popular AI tools out there, carries a vulnerability which allows threat actors to exfiltrate private user data, experts have warned.

Cybersecurity researcher Johann Rehberger, AKA Wunderwuzzi, who recently wrote an in-depth report on his findings, finding at the heart of the problem is Claude’s Code Interpreter, a sandboxed environment that lets AI write and run code (for example, to analyze data or generate files) directly within a conversation.





Source link