Post #3166140
2025-08-12 16:50 UTC
@kevlin@mastodon.social
apropos: https://embracethered.com/blog/posts/2025/claude-code-exfiltration-via-dns-requests/
Prompt injection through LLM allowing data exfiltration via DNS 😱
Surely state actors are working day and night looking for these issues and I am sure they have found plenty and are already exploiting them given how many folks are blindly using these tools w/ obviously bare or no code review at all.
The near universal lack of skepticism around these products has to be one of the biggest gift to black hats in a long long time.
Replies (0)
No replies.