每日 Harness 开源 · Source
返回本期 · Back to 2026-06-10

行业动态 · Industry News2026-06-10 · Wednesday, June 10, 2026

Microsoft's open source tools were hacked to steal passwords of AI developers

techcrunch.com原文 ↗

TechCrunch 报道 Microsoft 相关开源工具被攻击者植入 credential stealer,目标包括 AI developers。供应链攻击在 AI 开发场景尤其危险,因为本地环境通常同时持有模型 API keys、GitHub tokens、云凭据和生产访问路径。它和 agent 工具安全相互呼应:开发者安装的每个 CLI、插件和依赖都可能成为代理可触达的凭据入口。
浏览

评论 · Comments