The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Red teamers turned Claude Desktop into a double agent to do their evil bidding

EXCLUSIVE Pentera Labs’ red teamers compromised a developer’s AI agent via his Claude Desktop app and ultimately turned that access into full remote code execution on the dev’s machine – demonstrating how an attacker could turn a trusted, chatty AI assistant into a double agent operating on their behalf. “Claude’s got a new voice,” Pentera's offensive security services team leader Dvir Avraham told The Register. “We acknowledge the huge trust in AI models – everybody uses them,” he said in a phone interview. “We used this trust to manipulate the victim, like under the hood, the victim didn't see it coming.” It also prompted Avraham to check his own platforms. “I became a little bit paranoid,” he told us. “I'm not allowing any command to run without me examining it twice.” In a report set to publish Wednesday, and shared in advance exclusively with The Register, Avraham and research technical lead Reef Spektor detailed the attack and what it means for organizations using agentic AI tools with local code-execution access. It began with a red-team assignment on a third-party platform that aggregates customer email inboxes into a single management interface. Avraham and Spektor won’t name the platform, or tell us exactly how they gained access to it. They used this compromised inbox – and told us any compromised inbox would work – to get into the victim’s Claude account. As the duo noted, breaking into an email inbox in real life – via a third-party management platform, phishing link, social engineering password reset, or even using AI agents – isn’t too difficult. “AI agents today have access to connectors and to direct MCPs into inboxes,” Spektor added. In addition to this prerequisite (compromised inbox), the attack chain also requires the victim to have Claude Desktop installed. Anthropic’s desktop app works across macOS, Windows, and Linux systems. It provides the same AI chat for conversations as claude.ai, and it also syncs across all devices and sessions tied to the user’s account. “We asked ourselves, can we leverage the sync behavior to infect other sessions and devices? (hint: yes!),” the red teamers wrote in the Wednesday report. Back to the AI Stone Age As of January, the desktop app also includes Cowork for longer agentic tasks, and Code for software development. So, for example, a user can send Claude a task from their phone and instruct it to work on their computer. As Anthropic says: “Anything you can do on your computer, Claude can do. Open apps, fill spreadsheets, navigate your browser. No setup, no passwords handed off.” The Cowork feature now makes Pentera Labs’ attack scenario even easier. However, when the security analysts were doing this research in November 2025, “back in the Stone Age in terms of AI, you didn't have Cowork or Claude Code, so we needed a way to actually execute commands because we wanted to take over the machine,” Avraham said. For this part, they took a keen interest in Claude Desktop’s personalization features. These are account-wide settings that tell the AI agent the user’s preferred approach and general communication instructions, along with more specific project instructions, such as guidelines for a particular workflow, or defined roles Claude should adopt within a project. The red teamers developed a base64-encoded prompt that instructed Claude to check for command-capable tools on the developer’s machine and execute the command if available, or produce a fake error message if not, prompting the user to download a tool that will execute the attacker’s commands. Then they pasted the prompt into the victim’s personal preferences on Claude, and this prompt syncs across all of the user’s devices. This ensures that the next time the user opens Claude Desktop and types in a chat, the poisoned instructions are loaded into their preferences and will silently run behind the scenes. The user thinks they are simply interacting with Claude as usual. They don’t see Claude checking to see what extensions and tools are installed. If the user already has Desktop Commander or a similar MCP connector or extension installed, the poisoned instructions tell Claude to use it. This allows the attacker, via Claude, to execute a stealthy reverse shell or other malicious code. “And from there it's full compromise of the machine,” Avraham said. Phishing - but without the email However, if there aren’t any command-capable tools installed, then Claude becomes what the researchers describe as a “phishing layer.” (They also noted that if they had performed this research more recently, not back in November, the Claude Cowork feature would have eliminated this entire tool enumeration and phishing phase because Cowork can execute commands on a user’s behalf.) The injected prompt instructs Claude to present a realistic-looking error as soon as the victim asks the chatbot a question. This includes a realistic error code, a link that purports to be a fix, and step-by-step instructions. “This message tells the victim: ‘please download this,’ and we took links from the actual Anthropic site, with known emojis that the AI loves,” Avraham said. Because the error message looks real and people usually trust their AI assistant, they will likely click on the link and execute the attacker-controlled command. “From here, the attacker has full command execution – reverse shells, data exfiltration, credential harvesting, whatever the objective calls for,” the duo wrote. “In our case, we had Claude curl a remote server we controlled on every interaction, fetching and executing whatever bash commands we served back. We could rotate those commands server side at will, effectively turning Claude into a persistent, stealthy C2 agent that the victim themselves kept feeding.” In this specific case, the target was a developer who had credentials and access to several internal systems. After compromising the dev’s workstation – which gave the red teamers a foothold into the organization – they moved laterally across the company using various attack vectors that they declined to tell us about, citing customer privacy and proprietary methods. But, Spektor added, developers make for an “excellent starting point for an attacker,” because of their access to secrets including API keys, tokens, and cloud credentials, which allows intruders to move from a single workstation into the larger organization’s cloud environment. From there, they’ve got free rein to steal source code and other sensitive data, or poison internal git repositories, and cause all sorts of pain for enterprises as we've seen play out multiple times across several recent attacks. Feature, not a bug The team reported their findings to Anthropic back in November, and the AI company essentially said it’s Claude Desktop working as intended – a feature, not a bug. “After reviewing your submission, we've determined this doesn't represent a security vulnerability that falls within our program scope,” Anthropic said. “Our current threat model treats personal preferences, skills, and MCP connectors as features that can execute code through Claude Desktop by design. While we recognize these features can be leveraged to execute arbitrary code when manipulated, this represents expected functionality rather than a security vulnerability in our infrastructure.” The Register reached out to Anthropic for comment and did not receive any response. The red teamers, however, have some suggestions to keep your organization safer from rogue AI agents. First, for anyone using agents or chatbots: pay close attention to what the AI can do on your machine, and don’t blindly follow install prompts or error messages. “If you can, run it on a sandbox and not on your personal computer,” Spektor said. Security teams should treat AI desktop apps as “privileged software” as they can execute code, read files, and interact with local tools. “Monitor for changes of AI assistant configurations and synced settings,” the researchers wrote. “Restrict which extensions and tools can be installed alongside AI apps.” And finally, red teams should add AI desktop apps to their assessment toolbox, Avraham and Spektor noted: “There's a real attack surface here that most engagements don’t cover yet.” ®

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Ebolavirus verspreidt zich verder door Congo, vierde provincie bereikt

Nog steeds overheerst de scepsis tijdens Ketikoti: ‘Die nationale feestdag, die gaat niet gebeuren’

Congo gaat rust in met voorsprong tegen Engeland

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Paul May obituary

Tireless campaigner against miscarriages of justice who helped to secure the release of the Birmingham Six

In 1985 Paul May, who has died aged 74 of a pulmonary embolism, became the chair of the Birmingham Six campaign. Six years later, the convictions of Billy Power, Paddy Hill, Johnnie Walker, Richard McIlkenny, Gerry Hunter and Hughie Callaghan for the Birmingham pub bombings in 1974 were quashed by the court of appeal, but only after they had spent 17 years in prison.

As the campaign got under way from a small backroom in the Camden Irish Centre, north London, the journalist (and later Labour MP) Chris Mullin presented new evidence in World in Action TV programmes and a book. Alongside his work as a housing officer for Islington council, Paul expanded the campaign until it had a huge network of supporters in Britain and abroad. By the time the Six’s new appeal opened, he had done much to sway public opinion concerning one of the worst miscarriages of justice in British history, and he organised or was involved with such cases for the rest of his life.

Continue reading...

Crypto, bibles and watches: how Trump made over $2bn last year - The Latest

President Trump cashed in on more than $2bn from crypto and other businesses ventures last year.

As the US races to become the self‑declared ‘crypto capital of the world’, the president and his family have turned digital tokens, meme coins and merchandise into an unprecedented revenue stream.

But just how rich can a sitting US president get? Lucy Hough speaks to the Guardian reporter Aisha Down

Continue reading...

NASA’s Webb Studies How Planet Survived Death of its Star (Transmission Spectrum)

James Webb Space Telescope posted a photo:

NASA’s Webb Studies How Planet Survived Death of its Star (Transmission Spectrum)

NASA’s James Webb Space Telescope measured the constituents of exoplanet WD 1856 b's atmosphere as it passed in front of its star, finding signs of methane. WD 1856 b orbits a white dwarf star the size of Earth. As a result, the planet blocks more than half of the star’s light. The red bands indicate where bumps in the spectrum show that this planet’s atmosphere contains methane.

Read the full story: science.nasa.gov/missions/webb/nasas-webb-studies-how-pla...

Image Credit: Illustration: NASA, ESA, CSA, Joseph Olmsted (STScI)

Image Description: Graphic titled “Gas giant exoplanet WD 1856 b, transmission spectrum, NIRSpec PRISM” shows a graph of amount of light blocked by percent on the y-axis and wavelength of light in microns on the x-axis. The y-axis ranges from 55.2% to 56.5% with tick marks every 0.1% and labels at 55.5 and 56.0. The x-axis ranges from 0.5 to 4.0 microns with tick marks every 0.5 microns. A thick purple line outlined with two semi-translucent bands has an inner line that’s darker and an outer line that’s lighter. The purple line is wavy and runs higher, in the top third, until about 3.5 microns, where it drops to 55.2 on the y-axis and 4.0 on the x-axis. Five humps are highlighted by vertical red bars, indicating the presence of methane. White circles representing data points are scattered above and below the purple line. A key shows that the purple line is the best fit model, red highlights methane, and white circles represent data.

NASA’s Webb Studies How Planet Survived Death of its Star

James Webb Space Telescope posted a photo:

NASA’s Webb Studies How Planet Survived Death of its Star

You’re a spark in the dark 🎶

Billions of years ago, a Sun-like star nearing the end of its life swelled and became a red giant before ejecting its outer layers and leaving behind its core as a white dwarf. The transformation into a red giant should have destroyed any nearby planets, but astronomers found WD 1856 b, a Jupiter-sized exoplanet, orbiting the white dwarf in a tight orbit, every 34 hours at a distance of less than 2 million miles (3 million km). Could this planet actually have survived the death of its star? Or did this planet originate further out and migrate inwards due to gravitational effects of the other stars in this triple star system?

Using Webb, scientists were able to measure the temperature of this planet and show that it is significantly hotter than if the only source of its heat was the white dwarf. So the planet’s heat must be residual from an earlier time. Figuring out how early would help determine whether the heating came from being engulfed by a red giant or whether it occurred during an inward migration. The conclusion is that heating of this planet most likely happened between 3 and 5.5 billion years after the star became a red dwarf. Webb also took a look at the atmosphere of this planet which shows signs of methane.

In approximately five billion years, the Sun will run out of hydrogen fuel in its core and swell up more than 100 times larger than it is now into a red giant star. It will then shed its outer layers and end its life as a white dwarf star. Mercury, Venus, and possibly the Earth will be destroyed by the red giant. However, the fate of the more distant planets, particularly the gas giants, is unclear. Finding and studying planets in orbit around the remnants of Sun-like stars after their death is a means of learning what might happen in our own solar system in the far future.

Read more: science.nasa.gov/missions/webb/nasas-webb-studies-how-pla...

Image credit: Artwork: NASA, ESA, CSA, Ralf Crawford (STScI)

Image description: An orange gas giant planet at left, taking up about one-third of the frame, facing a star, which appears at top right as a far smaller bright dot. The planet has subtle orange cloud bands. The star illuminates the right side of the planet like the crescent of a waxing moon. Both are on the black background of space. The words “artist’s concept” are in the bottom right corner.

Wel.nl

Minder lezen, Meer weten.

Proces tegen Maltese zakenman voor moord op journalist begonnen

VALLETTA (ANP) - In Malta is de langverwachte rechtszaak tegen de rijke zakenman Yorgen Fenech begonnen. Hij wordt ervan verdacht in 2017 opdracht te hebben gegeven voor de moord op de bekende onderzoeksjournalist Daphne Caruana Galizia. De zaak leidde tot grote ophef in Malta en kostte onder meer de premier zijn baan.

Galizia deed uitgebreid onderzoek naar corruptie en vriendjespolitiek in de top van het Maltese bedrijfsleven en de politiek. Ze kwam op 53-jarige leeftijd om bij een bomaanslag op haar auto.

Eerder zijn al vijf personen veroordeeld voor het plaatsen of leveren van de bom, maar Fenech wordt gezien als de opdrachtgever achter de moord. Hij heeft een zakenimperium dat honderden miljoenen waard is en is onder meer actief in de energie- en toerismesector.

Levenslang

Fenech werd in 2019 gearresteerd op zijn jacht toen hij probeerde om Malta varend te verlaten. Iemand die betrokken was bij de moord had vlak daarvoor een deal gesloten met justitie om alle betrokkenen aan te wijzen.

Aanklagers eisten eerder al levenslang voor Fenech. Woensdag is de jury benoemd en daarmee kan de inhoudelijke zaak beginnen.

De familie van Galizia is blij dat het negen jaar na de moord zover is. Ook de internationale persvrijheidsorganisatie Reporters Without Borders schrijft op sociale media dat het proces "nieuwe hoop geeft dat er eindelijk gerechtigheid zal worden gedaan voor een misdrijf dat bijna negen jaar geleden is gepleegd".


Jaap van Dissel hekelt tijdens zijn tweede coronaverhoor „de spaghettibrij, de wirwar aan kabinetsmaatregelen”

De eerste getuige die twee keer langskomt bij de enquêtecommissie is Jaap van Dissel, woensdagmiddag.