作者的Mac Mini通过CVE-2026-65400漏洞遭到黑客入侵1。该漏洞存在于macOS屏幕共享功能中,严重程度评分为7.1/101。苹果官方表示该漏洞"可能"允许攻击者在没有凭证的情况下获得Mac访问权1。荷兰国家网络安全中心报告称,已在多个可从互联网访问5900端口的系统上观察到主动滥用行为,所有情况下都获得了root访问权限并放置了Monero加密矿工1。
Claude AI代理在此次入侵中主动检测到异常并阻止了恶意命令执行1,作者由此成功定位并清除了恶意软件1。作者的设备为一台持续运行的Mac Mini,上面仅运行Claude和Codex1。
苹果已于本周发布了对macOS Tahoe、Sequoia和Sonoma的补丁1。该漏洞详情在Black Hat安全会议上公开披露1。此外,苹果还发布了《macOS中全磁盘访问的更新》公告,限制了代理程序的访问权限1。
A Mac Mini running always-on Claude and Codex agents fell victim to a serious vulnerability in Apple's screen sharing functionality, according to an account shared on Hacker News 1. The flaw, designated CVE-2026-65400 with a severity rating of 7.1 out of 10, was recently disclosed at the Black Hat security conference and allows attackers to gain access to Mac systems without requiring credentials 1. Apple has since released patches addressing the vulnerability across macOS Tahoe, Sequoia, and Sonoma 1.
The breach gained particular attention because the Claude AI agent running on the compromised system independently detected anomalous activity and successfully blocked the malicious command execution, ultimately helping the user locate and remove the installed malware 1. According to the Dutch National Cyber Security Centre, the flaw has been actively exploited in multiple internet-accessible systems with port 5900 exposed, with attackers achieving root-level access and deploying Monero cryptocurrency miners in all observed cases 1. Apple's official security advisory characterized CVE-2026-65400 as potentially allowing attackers to gain access to affected Macs without valid credentials 1.
The incident has prompted Apple to issue updated guidance on full disk access permissions for agent programs, reflecting broader concerns about how the company is balancing security restrictions with the operational needs of increasingly autonomous AI applications 1.
评论
还没有评论,欢迎留下第一条。