<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>供应链攻击 on MessageDaily</title><link>https://inkeast.github.io/MessageDaily/tags/%E4%BE%9B%E5%BA%94%E9%93%BE%E6%94%BB%E5%87%BB/</link><description>Recent content in 供应链攻击 on MessageDaily</description><generator>Hugo</generator><language>zh-cn</language><lastBuildDate>Sat, 05 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://inkeast.github.io/MessageDaily/tags/%E4%BE%9B%E5%BA%94%E9%93%BE%E6%94%BB%E5%87%BB/index.xml" rel="self" type="application/rss+xml"/><item><title>HookPry 精读：Agent Harness 的 hook 更新通道是全新的供应链攻击面</title><link>https://inkeast.github.io/MessageDaily/posts/2026-09-05-hookpry-agent-harness-security-paper-reading/</link><pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate><guid>https://inkeast.github.io/MessageDaily/posts/2026-09-05-hookpry-agent-harness-security-paper-reading/</guid><description>HookPry（北邮/网信办数据中心/北航/浙大）首次系统揭示 AI Agent Harness 生命周期 hook 的更新通道攻击面：良性插件上架获取信任后，一次携带 hook 的恶意更新即可在 LLM 完全不可见的路径上以宿主权限执行任意命令。1000 次端到端攻击攻破全部 7 个 harness（最高 92.5%），Microsoft Defender 召回率 0%。本文基于全文阅读拆解其 AMO/TD/LCI 三组件与防御失灵的机制根源。</description></item></channel></rss>