Claude Cowork Exfiltrates Files (opens in new tab)
<p><strong><a href="https://www.promptarmor.com/resources/claude-cowork-exfiltrates-files">Claude Cowork Exfiltrates Files</a></strong></p> Claude Cowork defaults to allowing outbound HTTP traffic to only a specific list of domains, to help protect the user against prompt injection attacks that exfiltrate their data.</p> <p>Prompt Armor found a creative workaround: Anthropic's API domain is on that list, so they constructed an attack that includes an attacker's own Anthropic API key and has ...
Read the original article