Code execution through email: How I used Claude to hack itself
1–10 of 73 posts
Re: Code execution through email: How I used Claude to hack itself
#2Re: Code execution through email: How I used Claude to hack itself
#3Installing malware on your own computer with extra steps?
Re: Code execution through email: How I used Claude to hack itself
#4Installing malware on your own computer with extra steps?
Re: Code execution through email: How I used Claude to hack itself
#5Phishing an AI is kind of similar to phishing a smart-ish person...
So remind me again, why does an email scanner need code execution at all?
Re: Code execution through email: How I used Claude to hack itself
#6Re: Code execution through email: How I used Claude to hack itself
#7Yes, allowing code execution by untrustworthy agents, especially networked ones, is fraught with danger. Phishing an AI is kind of similar to phishing a smart-ish person... So remind me again, why does an email scanner need code execution at all?
Code execution is an optional backend capability for enabling certain workflows
Re: Code execution through email: How I used Claude to hack itself
#8But in this case and maybe others, AI is just a fancy scripting engine by name of LLMs.
Re: Code execution through email: How I used Claude to hack itself
#9Re: Code execution through email: How I used Claude to hack itself
#10In traditional security, everyone knows that attaching a code runner to a source of untrusted input is a terrible idea. AI plays no role in this.
> That’s exactly why we’re building MCP Security at Pynt, to help teams identify dangerous trust-capability combinations, and to mitigate the risks before they lead to silent, chain-based exploits.
This post just an add then?