Automatically translated.View original post

A new method of attack was found, Ghostcommitted.

New attack method found Ghostcommit can fool AI assistant by hiding Prompt in pictures

According to a report by the official website of the developer of the famous anti-malware tool, Malwarebytes, a research team from ASSET Research Group has discovered a new strategy to secretly embed instructions within an image file to command the AI programming assistance type (Coding Agent) to follow what it wants, such as read and send Sensitive Information to hackers. To do this, two types of files are required: Configuration Files. In this experiment, a file called AGENTS.md and a genus image file. PNG with secretly hiding commands that command reading and stealing sensitive data.

It starts by having the AI read the setup file. Whether it is checked by people or the AI does not find anything wrong inside, and human users generally do not do in-depth inspection of the image file. After having the AI read the setup file, it will find a Referred point. The AI will read the attached image file again. When the AI reads the command file of the image and immediately follows the instructions embedded by the hackers. By this method, the research team named it Ghostcommit. Currently, this method is still in step. The idea test or Proof of Concept is not yet used by real hackers. In that test, the research team determined that the method does not result in the same AI. Each model by Cursor and Antigravity follows the steps specified in the PNG file. But the Claude Code reads the embedded commands as well but refuses to do so. Therefore, the method is not a complete method, as it is subject to conditions to work.

# Trending # Lemon 8 Howtoo # lemon 8 diary # Ghostcommitted # freedomhack

4 days agoEdited to

... Read moreจากประสบการณ์การศึกษาวิธีการโจมตีทางเทคนิคล่าสุดอย่าง Ghostcommit พบว่า การซ่อนคำสั่งในรูปภาพที่ส่งให้ AI ช่วยเขียนโปรแกรมนั้นสร้างความท้าทายอย่างมาก เนื่องจาก AI จะอ่านข้อมูลจากไฟล์ตั้งค่า AGENTS.md ที่ไม่มีสัญญาณผิดปกติ ทำให้ผู้ใช้ทั่วไปหรือแม้แต่ระบบป้องกันไม่สามารถตรวจจับได้ง่ายๆ สิ่งสำคัญที่ผมได้เรียนรู้คือ การโจมตีนี้ใช้ประโยชน์จากการที่มนุษย์มักไม่ตรวจสอบไฟล์รูปภาพเชิงลึก พอ AI อ่านคำสั่งในรูปภาพ PNG แล้วก็ทำตามคำสั่งทันทีก่อให้เกิดความเสี่ยงในการรั่วไหลข้อมูลอ่อนไหว เช่น คีย์ลับ หรือ environment variables ที่ถูกฝังเป็นตัวเลขในภาพตามที่ OCR สแกนได้ การโจมตีรูปแบบนี้ยังไม่ได้ใช้ในทางปฏิบัติจริงและยังอยู่ในขั้นตอนการทดสอบ แต่สิ่งที่ผู้พัฒนาควรทำคือเพิ่มความระมัดระวังในเรื่องการอ่านไฟล์ตั้งค่าและไฟล์แนบโดย AI เช่น จำกัดขอบเขตการประมวลผลไฟล์รูปภาพ หรือเสริมความสามารถตรวจสอบคำสั่งแปลกปลอมที่อาจแฝงอยู่ นอกจากนี้ บางโมเดล AI อย่าง Claude Code ยังมีการปฏิเสธทำตามคำสั่งที่ฝังในภาพ ซึ่งแสดงให้เห็นความแตกต่างและช่องว่างด้านความปลอดภัยของ AI แต่ละตัว ซึ่งในอนาคตผู้พัฒนาควรให้ความสำคัญกับการออกแบบระบบตรวจจับคำสั่งแอบแฝงเหล่านี้อย่างจริงจัง เพื่อป้องกันการโจมตีและการรั่วไหลข้อมูล จากการทดลองนี้ ผมคิดว่าเป็นโอกาสดีที่ผู้ใช้งานทั่วไปจะได้เรียนรู้ถึงความเสี่ยงใหม่ๆ ของ AI และการจัดการข้อมูลที่ส่งเข้าไปอย่างรอบคอบ เพื่อไม่ให้ตกเป็นเหยื่อจากเทคนิคที่ซับซ้อนนี้ในอนาคต