{"@context":"https://schema.org","@type":"NewsArticle","generatedAt":"2026-07-28T06:20:51.496Z","headline":"Anthropic 称 Opus 5 几乎免疫浏览器提示词注入，攻击成功率降至零","description":"Anthropic 称其 Opus 5 模型在自家软件中几乎免疫提示词注入攻击。在 129 个浏览器智能体测试场景中，攻击成功率为零；在 Gray Swan 通用提示词注入测试中，15 次尝试后的成功率从 Opus 4.8 的 5.5% 降至 2.0%。零成功率仅在 Claude Cowork 等产品开启 Auto Mode 时实现，该模式叠加了输入扫描与执行拦截两层防御。","url":"https://www.aioga.com/news/cms0942e500corodza9v7s7sb/","mainEntityOfPage":"https://www.aioga.com/news/cms0942e500corodza9v7s7sb/","datePublished":"2026-07-25T10:43:36.000Z","dateModified":"2026-07-25T10:43:36.000Z","inLanguage":"zh-CN","publisher":{"@type":"NewsMediaOrganization","name":"Aioga","url":"https://www.aioga.com"},"citation":["https://the-decoder.com/opus-5-may-have-solved-browser-based-prompt-injection-the-biggest-security-flaw-haunting-ai-agents","https://aihot.virxact.com/items/cms0942e500corodza9v7s7sb"],"canonicalUrl":"https://www.aioga.com/news/cms0942e500corodza9v7s7sb/","directAnswer":{"@type":"Answer","text":"Aioga 编辑摘要：Anthropic 称其 Opus 5 模型在自家软件中几乎免疫提示词注入攻击。 Aioga 将其归入「模型更新」方向，重点关注它对真实使用和行业竞争的影响。","url":"https://www.aioga.com/news/cms0942e500corodza9v7s7sb/","dateCreated":"2026-07-25T10:43:36.000Z","author":{"@type":"Organization","@id":"https://www.aioga.com/authors/aioga-editorial/#editorial-team","name":"Aioga Editorial Team","url":"https://www.aioga.com/authors/aioga-editorial/"}},"evidence":[{"@type":"CreativeWork","name":"the-decoder.com source article","url":"https://the-decoder.com/opus-5-may-have-solved-browser-based-prompt-injection-the-biggest-security-flaw-haunting-ai-agents","datePublished":"2026-07-25T10:43:36.000Z","provider":{"@type":"Organization","name":"the-decoder.com","url":"https://the-decoder.com/opus-5-may-have-solved-browser-based-prompt-injection-the-biggest-security-flaw-haunting-ai-agents"}},{"@type":"CreativeWork","name":"AIHot archive record","url":"https://aihot.virxact.com/items/cms0942e500corodza9v7s7sb","datePublished":"2026-07-25T10:43:36.000Z","provider":{"@type":"Organization","name":"AIHot","url":"https://aihot.virxact.com/items/cms0942e500corodza9v7s7sb"}}],"aggregationSource":"The Decoder：AI News（RSS）","originalPublisher":{"name":"the-decoder.com","url":"https://the-decoder.com/opus-5-may-have-solved-browser-based-prompt-injection-the-biggest-security-flaw-haunting-ai-agents"},"article":{"id":"cms0942e500corodza9v7s7sb","slug":"cms0942e500corodza9v7s7sb","url":"https://www.aioga.com/news/cms0942e500corodza9v7s7sb/","title":"Anthropic 称 Opus 5 几乎免疫浏览器提示词注入，攻击成功率降至零","title_en":"Opus 5 may have solved browser-based prompt injection， the biggest security flaw haunting AI agents","summary":"Anthropic 称其 Opus 5 模型在自家软件中几乎免疫提示词注入攻击。在 129 个浏览器智能体测试场景中，攻击成功率为零；在 Gray Swan 通用提示词注入测试中，15 次尝试后的成功率从 Opus 4.8 的 5.5% 降至 2.0%。零成功率仅在 Claude Cowork 等产品开启 Auto Mode 时实现，该模式叠加了输入扫描与执行拦截两层防御。","source":"The Decoder：AI News（RSS）","sourceUrl":"https://the-decoder.com/opus-5-may-have-solved-browser-based-prompt-injection-the-biggest-security-flaw-haunting-ai-agents","aiHotUrl":"https://aihot.virxact.com/items/cms0942e500corodza9v7s7sb","publishedAt":"2026-07-25T10:43:36.000Z","category":"模型更新","score":60,"selected":false,"articleBody":["Anthropic says Opus 5 is nearly immune to prompt injections in its own software. Prompt injection：https://the-decoder.com/claude-cowork-hit-with-file-stealing-prompt-injection-days-after-anthropics-launch/, where an attacker slips past an AI model's instructions through manipulated inputs like hidden text on a webpage, fails against Opus 5 in almost every case. For browser agents, the attack success rate hit zero percent across 129 test scenarios, per the system card：https://www-cdn.anthropic.com/c5fbac3f0b1280a933ebd26d3cb8bb9f5bdeaf48/Claude%20Opus%205%20System%20Card.pdf#page=76. That's a big deal given that OpenAI admitted in December that prompt injection may never be fully solved：https://the-decoder.com/openai-admits-prompt-injection-may-never-be-fully-solved-casting-doubt-on-the-agentic-ai-vision/. In a general prompt injection test by security firm Gray Swan：https://www.grayswan.ai/, the success rate after 15 attempts dropped from 5.5 percent (Opus 4.8) to 2.0 percent.","That zero percent rate only holds with Auto Mode turned on in products like Claude Cowork：https://www.anthropic.com/engineering/claude-code-auto-mode. Auto Mode stacks two defense layers. One scans incoming data for hidden instructions before the model processes them. The other blocks dangerous actions before execution. An attacker has to beat both independently. Without them, Opus 5 sits at 3.7 percent, and Sonnet 5 actually does better at 0.93 percent. Only the combination of model and protective software pushes the rate to zero.","Stay in the loop on AI. Clear, useful, no fluff.","Follow The Decoder for AI news, background stories and expert analyses.","The Decoder：https://the-decoder.com/"],"articleImages":[{"sourceUrl":"https://the-decoder.com/wp-content/uploads/2026/07/opus_5_prompt_injections.jpg","alt":"Opus 5 schneidet im Gray Swan IPI-Benchmark am besten ab: Nach 15 Versuchen liegt die Erfolgsrate für Angreifer bei 2,0 %, gefolgt von Mythos 5 (2,6 %) und Fable 5 (2,8 %). | Bild: Anthropic","afterParagraph":0,"url":"/media/articles/cms0942e500corodza9v7s7sb/47246868030d2d5d.jpg"}],"mediaStatus":"ok","articleBodyZh":["Anthropic 表示 Opus 5 在其自有软件中几乎对提示注入免疫。提示注入：https://the-decoder.com/claude-cowork-hit-with-file-stealing-prompt-injection-days-after-anthropics-launch/，指攻击者通过网页上的隐藏文本等操纵输入，绕过 AI 模型的指令，这在几乎所有情况下对 Opus 5 都失败了。对于浏览器代理，根据系统手册：https://www-cdn.anthropic.com/c5fbac3f0b1280a933ebd26d3cb8bb9f5bdeaf48/Claude%20Opus%205%20System%20Card.pdf#page=76，129 个测试场景下攻击成功率为零。这很重要，因为 OpenAI 在去年 12 月承认提示注入可能永远无法完全解决：https://the-decoder.com/openai-admits-prompt-injection-may-never-be-fully-solved-casting-doubt-on-the-agentic-ai-vision/。在安全公司 Gray Swan：https://www.grayswan.ai/ 进行的一般提示注入测试中，经过 15 次尝试后的成功率从 5.5%（Opus 4.8）下降到 2.0%。","这个零成功率仅在 Claude Cowork 等产品开启自动模式时有效：https://www.anthropic.com/engineering/claude-code-auto-mode。自动模式叠加了两层防御。第一层在模型处理数据之前扫描输入数据中隐藏的指令。第二层在执行前阻止危险操作。攻击者必须分别击败这两层。没有这两层，Opus 5 的成功率为 3.7%，而 Sonnet 5 实际上表现更好，为 0.93%。只有模型与保护软件结合，才可将成功率降至零。","保持对 AI 的关注。清晰、有用、无废话。","关注 The Decoder 获取 AI 新闻、背景故事和专家分析。","The Decoder：https://the-decoder.com/"],"translationStatus":"translated","bodyOrigin":"source-page","editorial":{"summary":"Aioga 编辑摘要：Anthropic 称其 Opus 5 模型在自家软件中几乎免疫提示词注入攻击。 Aioga 将其归入「模型更新」方向，重点关注它对真实使用和行业竞争的影响。","background":"背景分析：模型与研究类动态需要结合能力边界、开放方式、成本、可用性和真实任务表现判断，单项指标领先不等于已经形成稳定采用。","viewpoint":"Aioga 判断：这条动态更适合作为行业观察信号，当前信息足以建立线索，但不足以推导长期结论。","implications":"影响分析：对相关团队而言，短期应先核对来源、可用范围和实际成本，再判断是否值得接入或跟进。","nextStep":"后续观察：继续观察官方文档、实际可用性、价格变化、开发者反馈和竞品回应。","evidenceRefs":["title","summary","articleBody"],"confidence":"medium","status":"published","aiGenerated":false,"autoApproved":true,"generatedBy":"rule-safe-fallback","generatedAt":"2026-07-28T06:29:10.509Z","sourceHash":"d93812ac4b41d90e","validation":{"passed":true,"mode":"rule-safe-fallback","checks":["schema","length","source-attribution","no-html"]}},"tags":["模型更新","The Decoder：AI News（RSS）"],"translations":{"zh-CN":{"title":"Anthropic 称 Opus 5 几乎免疫浏览器提示词注入，攻击成功率降至零","summary":"Anthropic 称其 Opus 5 模型在自家软件中几乎免疫提示词注入攻击。在 129 个浏览器智能体测试场景中，攻击成功率为零；在 Gray Swan 通用提示词注入测试中，15 次尝试后的成功率从 Opus 4.8 的 5.5% 降至 2.0%。零成功率仅在 Claude Cowork 等产品开启 Auto Mode 时实现，该模式叠加了输入扫描与执行拦截两层防御。","category":"模型更新","source":"the-decoder.com","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic 称 Opus 5 几乎免疫浏览器提示词注入，攻击成功率降至零 - Aioga AI资讯","description":"Anthropic 称其 Opus 5 模型在自家软件中几乎免疫提示词注入攻击。在 129 个浏览器智能体测试场景中，攻击成功率为零；在 Gray Swan 通用提示词注入测试中，15 次尝试后的成功率从 Opus 4.8 的 5.5% 降至 2.0%。零成功率仅在 Claude Cowork 等产品开启 Auto Mode 时实现，该模式叠加了输入扫描与执...","url":"https://www.aioga.com/news/cms0942e500corodza9v7s7sb/"},"en":{"title":"Anthropic says Opus 5 is almost immune to browser prompt injection, with the attack success rate dropping to zero","summary":"Anthropic claims that its Opus 5 model is almost immune to prompt injection attacks in its own software. In 129 browser agent test scenarios, the attack success rate was zero; in the Gray Swan general prompt injection test, the success rate after 15 attempts dropped from 5.5% for Opus 4.8 to 2.0%. A zero success rate was only achieved when products like Claude Cowork had Auto Mode enabled, which adds two layers of defense: input scanning and execution interception.","category":"Models","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic says Opus 5 is almost immune to browser prompt injection, with the attack success rate dropping to zero - Aioga AI News","description":"Anthropic claims that its Opus 5 model is almost immune to prompt injection attacks in its own software. In 129 browser agent test scenarios, the attack success rate was zero; in t...","url":"https://www.aioga.com/en/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:42:21.388Z"},"ja":{"title":"Anthropic は Opus 5 がほぼブラウザプロンプトインジェクションに免疫であり、攻撃成功率がゼロに下がったと述べている","summary":"Anthropic は、その Opus 5 モデルが自社ソフトウェア内でほぼプロンプトインジェクション攻撃に免疫であると述べています。129 のブラウザエージェントテストシナリオでは、攻撃成功率はゼロでした。Gray Swan の汎用プロンプトインジェクションテストでは、15 回の試行後の成功率は Opus 4.8 の 5.5% から 2.0% に低下しました。ゼロ成功率は、Claude Cowork などの製品で Auto Mode を有効にした場合にのみ実現され、このモードでは入力スキャンと実行インターセプトの二重防御が追加されています。","category":"モデル更新","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic は Opus 5 がほぼブラウザプロンプトインジェクションに免疫であり、攻撃成功率がゼロに下がったと述べている - Aioga AIニュース","description":"Anthropic は、その Opus 5 モデルが自社ソフトウェア内でほぼプロンプトインジェクション攻撃に免疫であると述べています。129 のブラウザエージェントテストシナリオでは、攻撃成功率はゼロでした。Gray Swan の汎用プロンプトインジェクションテストでは、15 回の試行後の成功率は Opus 4.8 の 5.5% から 2.0% に低下しまし...","url":"https://www.aioga.com/ja/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:42:31.435Z"},"ko":{"title":"Anthropic는 Opus 5가 브라우저 프롬프트 주입에 거의 면역하며 공격 성공률이 0으로 떨어졌다고 밝혔다","summary":"Anthropic는 자사의 Opus 5 모델이 자사 소프트웨어에서 거의 프롬프트 주입 공격에 면역이라고 주장합니다. 129개의 브라우저 에이전트 테스트 시나리오에서 공격 성공률은 0%였으며, Gray Swan 일반 프롬프트 주입 테스트에서는 15번 시도 후 성공률이 Opus 4.8의 5.5%에서 2.0%로 낮아졌습니다. 제로 성공률은 Claude Cowork 등 제품에서 Auto Mode를 켰을 때만 달성되며, 이 모드는 입력 스캔과 실행 차단이라는 두 겹의 방어를 더합니다.","category":"모델 업데이트","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic는 Opus 5가 브라우저 프롬프트 주입에 거의 면역하며 공격 성공률이 0으로 떨어졌다고 밝혔다 - Aioga AI 뉴스","description":"Anthropic는 자사의 Opus 5 모델이 자사 소프트웨어에서 거의 프롬프트 주입 공격에 면역이라고 주장합니다. 129개의 브라우저 에이전트 테스트 시나리오에서 공격 성공률은 0%였으며, Gray Swan 일반 프롬프트 주입 테스트에서는 15번 시도 후 성공률이 Opus 4.8의 5.5%에서 2.0%로 낮아졌습니다....","url":"https://www.aioga.com/ko/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:43:11.825Z"},"es":{"title":"Anthropic afirma que Opus 5 es casi inmune a la inyección de indicaciones en el navegador, la tasa de éxito del ataque se reduce a cero","summary":"Anthropic afirma que su modelo Opus 5 es casi inmune a los ataques de inyección de prompts en su propio software. En 129 escenarios de prueba con agentes de navegador, la tasa de éxito del ataque fue cero; en la prueba de inyección de prompts general Gray Swan, la tasa de éxito después de 15 intentos cayó del 5,5% de Opus 4.8 al 2,0%. La tasa de éxito cero solo se logra en productos como Claude Cowork cuando se activa el Modo Automático, que combina dos capas de defensa: escaneo de entradas e interceptación de ejecución.","category":"Modelos","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic afirma que Opus 5 es casi inmune a la inyección de indicaciones en el navegador, la tasa de éxito del ataque se reduce a cero - Aioga Noticias de IA","description":"Anthropic afirma que su modelo Opus 5 es casi inmune a los ataques de inyección de prompts en su propio software. En 129 escenarios de prueba con agentes de navegador, la tasa de é...","url":"https://www.aioga.com/es/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:43:10.361Z"},"fr":{"title":"Anthropic affirme qu'Opus 5 est presque immunisé contre l'injection de prompts dans le navigateur, le taux de réussite des attaques tombant à zéro","summary":"Anthropic affirme que son modèle Opus 5 est presque immunisé contre les attaques par injection de prompt dans ses propres logiciels. Dans 129 scénarios de test avec des agents intelligents de navigateurs, le taux de réussite des attaques était de zéro ; dans le test général d'injection de prompts Gray Swan, après 15 tentatives, le taux de réussite est passé de 5,5 % pour Opus 4.8 à 2,0 %. Un taux de réussite nul n'a été atteint que lorsque des produits comme Claude Cowork avaient activé le mode Auto, qui superpose deux couches de défense : la lecture des entrées et l'interception de l'exécution.","category":"Modèles","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic affirme qu'Opus 5 est presque immunisé contre l'injection de prompts dans le navigateur, le taux de réussite des attaques tombant à zéro - Aioga Actualités IA","description":"Anthropic affirme que son modèle Opus 5 est presque immunisé contre les attaques par injection de prompt dans ses propres logiciels. Dans 129 scénarios de test avec des agents inte...","url":"https://www.aioga.com/fr/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:43:49.932Z"},"de":{"title":"Anthropic sagt, dass Opus 5 fast immun gegen Browser-Prompt-Injektionen ist, die Angriffsrate auf null gesunken ist","summary":"Anthropic behauptet, dass sein Opus-5-Modell in der eigenen Software nahezu immun gegen Prompt-Injection-Angriffe ist. In 129 Test-Szenarien mit Browser-Agenten lag die Erfolgsrate der Angriffe bei null; im Gray-Swan-Standardtest für Prompt-Injection ging die Erfolgsrate nach 15 Versuchen von 5,5 % bei Opus 4.8 auf 2,0 % zurück. Eine Erfolgsrate von null wird nur erreicht, wenn Produkte wie Claude Cowork den Auto-Modus aktiviert haben, der eine doppelte Verteidigung aus Eingabescans und Ausführungsblockierungen kombiniert.","category":"模型更新","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic sagt, dass Opus 5 fast immun gegen Browser-Prompt-Injektionen ist, die Angriffsrate auf null gesunken ist - Aioga KI-News","description":"Anthropic behauptet, dass sein Opus-5-Modell in der eigenen Software nahezu immun gegen Prompt-Injection-Angriffe ist. In 129 Test-Szenarien mit Browser-Agenten lag die Erfolgsrate...","url":"https://www.aioga.com/de/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:43:50.036Z"},"pt-BR":{"title":"A Anthropic afirma que o Opus 5 é quase imune à injeção de prompts no navegador, com a taxa de sucesso de ataques caindo para zero","summary":"A Anthropic afirma que seu modelo Opus 5 é quase imune a ataques de injeção de prompts em seu próprio software. Em 129 cenários de teste com agentes inteligentes de navegador, a taxa de sucesso dos ataques foi zero; no teste geral de injeção de prompts Gray Swan, após 15 tentativas, a taxa de sucesso caiu de 5,5% do Opus 4.8 para 2,0%. A taxa de sucesso zero só é alcançada com produtos como Claude Cowork quando o Modo Automático está ativado, modo que combina duas camadas de defesa: varredura de entrada e interceptação de execução.","category":"模型更新","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"A Anthropic afirma que o Opus 5 é quase imune à injeção de prompts no navegador, com a taxa de sucesso de ataques caindo para zero - Aioga Notícias de IA","description":"A Anthropic afirma que seu modelo Opus 5 é quase imune a ataques de injeção de prompts em seu próprio software. Em 129 cenários de teste com agentes inteligentes de navegador, a ta...","url":"https://www.aioga.com/pt-BR/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:44:24.566Z"},"ru":{"title":"Anthropic заявляет, что Opus 5 практически не восприимчив к инъекциям подсказок в браузере, вероятность успешной атаки снижена до нуля","summary":"Компания Anthropic заявила, что их модель Opus 5 практически устойчива к атакам с внедрением подсказок в собственном программном обеспечении. В 129 тестовых сценариях с браузерными агентами успешность атаки составила ноль; в общем тесте внедрения подсказок Gray Swan после 15 попыток успешность снизилась с 5,5% в Opus 4.8 до 2,0%. Нулевая успешность достигается только при включении Auto Mode в продуктах вроде Claude Cowork, этот режим накладывает два уровня защиты: сканирование ввода и блокировку выполнения.","category":"模型更新","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic заявляет, что Opus 5 практически не восприимчив к инъекциям подсказок в браузере, вероятность успешной атаки снижена до нуля - Aioga Новости ИИ","description":"Компания Anthropic заявила, что их модель Opus 5 практически устойчива к атакам с внедрением подсказок в собственном программном обеспечении. В 129 тестовых сценариях с браузерными...","url":"https://www.aioga.com/ru/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:44:30.453Z"},"ar":{"title":"تقول شركة Anthropic إن Opus 5 شبه محصن ضد إدخال تلميحات المتصفح، وانخفض معدل نجاح الهجوم إلى الصفر","summary":"تقول شركة Anthropic إن نموذجها Opus 5 يكاد يكون محصناً ضد هجمات حقن التعليمات البرمجية في برامجها الخاصة. في 129 سيناريو اختبار لوكلاء المتصفح، كانت نسبة نجاح الهجوم صفرًا؛ وفي اختبار حقن التعليمات البرمجية العام Gray Swan، انخفضت نسبة النجاح بعد 15 محاولة من 5.5% في Opus 4.8 إلى 2.0%. تم تحقيق نسبة نجاح صفرية فقط عند تفعيل وضع Auto Mode في منتجات مثل Claude Cowork، حيث يجمع هذا الوضع بين مسح المدخلات واعتراض التنفيذ كطبقتين من الدفاع.","category":"模型更新","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"تقول شركة Anthropic إن Opus 5 شبه محصن ضد إدخال تلميحات المتصفح، وانخفض معدل نجاح الهجوم إلى الصفر - Aioga أخبار الذكاء الاصطناعي","description":"تقول شركة Anthropic إن نموذجها Opus 5 يكاد يكون محصناً ضد هجمات حقن التعليمات البرمجية في برامجها الخاصة. في 129 سيناريو اختبار لوكلاء المتصفح، كانت نسبة نجاح الهجوم صفرًا؛ وفي اخت...","url":"https://www.aioga.com/ar/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:45:08.820Z"},"hi":{"title":"Anthropic का कहना है कि Opus 5 लगभग ब्राउज़र प्रॉम्प्ट इंजेक्शन के प्रति प्रतिरक्षित है, और हमलों की सफलता दर शून्य तक कम हो गई है","summary":"Anthropic ने कहा कि उसका Opus 5 मॉडल अपने सॉफ़्टवेयर में लगभग पूरी तरह से प्रॉम्प्ट इंजेक्शन हमलों के प्रति प्रतिरक्षित है। 129 ब्राउज़र एजेंट परीक्षण परिदृश्यों में, हमला सफलता दर शून्य थी; Gray Swan सामान्य प्रॉम्प्ट इंजेक्शन परीक्षण में, Opus 4.8 से सफलता दर 5.5% से घटकर 15 प्रयासों के बाद 2.0% हो गई। शून्य सफलता दर केवल तब प्राप्त की गई जब Claude Cowork जैसे उत्पादों में ऑटो मोड चालू था, जिसमें इनपुट स्कैनिंग और निष्पादन अवरोधन की दो परतें शामिल थीं।","category":"模型更新","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic का कहना है कि Opus 5 लगभग ब्राउज़र प्रॉम्प्ट इंजेक्शन के प्रति प्रतिरक्षित है, और हमलों की सफलता दर शून्य तक कम हो गई है - Aioga AI समाचार","description":"Anthropic ने कहा कि उसका Opus 5 मॉडल अपने सॉफ़्टवेयर में लगभग पूरी तरह से प्रॉम्प्ट इंजेक्शन हमलों के प्रति प्रतिरक्षित है। 129 ब्राउज़र एजेंट परीक्षण परिदृश्यों में, हमला सफलता दर...","url":"https://www.aioga.com/hi/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:45:10.110Z"},"it":{"title":"Anthropic afferma che Opus 5 è quasi immune all'iniezione di prompt nel browser, con il tasso di successo degli attacchi che scende a zero","summary":"Anthropic afferma che il suo modello Opus 5 è quasi immune agli attacchi di prompt injection nel proprio software. Nei 129 scenari di test con agenti del browser, il tasso di successo degli attacchi è stato pari a zero; nel test di prompt injection universale Gray Swan, il tasso di successo dopo 15 tentativi è sceso dal 5,5% di Opus 4.8 al 2,0%. Il tasso di successo zero si è ottenuto solo attivando la Auto Mode in prodotti come Claude Cowork, modalità che combina due livelli di difesa: scansione dell’input e intercettazione dell’esecuzione.","category":"模型更新","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic afferma che Opus 5 è quasi immune all'iniezione di prompt nel browser, con il tasso di successo degli attacchi che scende a zero - Aioga Notizie IA","description":"Anthropic afferma che il suo modello Opus 5 è quasi immune agli attacchi di prompt injection nel proprio software. Nei 129 scenari di test con agenti del browser, il tasso di succe...","url":"https://www.aioga.com/it/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:45:51.633Z"},"nl":{"title":"Anthropic zegt dat Opus 5 bijna immuun is voor browser prompt-injecties, en dat het slagingspercentage van aanvallen tot nul is gedaald","summary":"Anthropic zegt dat hun Opus 5-model vrijwel immuun is voor prompt-injectieaanvallen in hun eigen software. In 129 testsituaties met browseragents was het slagingspercentage van de aanvallen nul; in de Gray Swan algemene prompt-injectietest daalde het slagingspercentage na 15 pogingen van 5,5% bij Opus 4.8 naar 2,0%. Een slagingspercentage van nul werd alleen bereikt wanneer producten zoals Claude Cowork de Auto Mode inschakelden, die twee verdedigingslagen combineert: invoerscanning en uitvoeringsinterceptie.","category":"模型更新","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic zegt dat Opus 5 bijna immuun is voor browser prompt-injecties, en dat het slagingspercentage van aanvallen tot nul is gedaald - Aioga AI-nieuws","description":"Anthropic zegt dat hun Opus 5-model vrijwel immuun is voor prompt-injectieaanvallen in hun eigen software. In 129 testsituaties met browseragents was het slagingspercentage van de...","url":"https://www.aioga.com/nl/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:45:47.544Z"},"tr":{"title":"Anthropic, Opus 5'in tarayıcı istemi enjeksiyonuna karşı neredeyse bağışık olduğunu ve saldırı başarı oranının sıfıra düştüğünü açıkladı","summary":"Anthropic, Opus 5 modelinin kendi yazılımında neredeyse prompt enjeksiyon saldırılarına karşı bağışık olduğunu belirtiyor. 129 tarayıcı ajanı test senaryosunda saldırı başarısı oranı sıfır oldu; Gray Swan genel prompt enjeksiyon testi sonucunda 15 denemeden sonra başarı oranı Opus 4.8'deki %5,5'ten %2,0'ye düştü. Sıfır başarı oranı yalnızca Claude Cowork gibi ürünlerde Otomatik Mod açıldığında gerçekleşti; bu mod, giriş taraması ve yürütme engellemenin iki katmanlı savunmasını birleştiriyor.","category":"模型更新","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic, Opus 5'in tarayıcı istemi enjeksiyonuna karşı neredeyse bağışık olduğunu ve saldırı başarı oranının sıfıra düştüğünü açıkladı - Aioga AI Haberleri","description":"Anthropic, Opus 5 modelinin kendi yazılımında neredeyse prompt enjeksiyon saldırılarına karşı bağışık olduğunu belirtiyor. 129 tarayıcı ajanı test senaryosunda saldırı başarısı ora...","url":"https://www.aioga.com/tr/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:46:33.267Z"},"vi":{"title":"Anthropic cho biết Opus 5 gần như miễn dịch với việc tiêm từ khóa trình duyệt, tỷ lệ tấn công thành công giảm xuống bằng không","summary":"Anthropic cho biết mô hình Opus 5 của họ gần như miễn nhiễm với các cuộc tấn công chèn từ khóa trong phần mềm riêng của họ. Trong 129 kịch bản thử nghiệm trình duyệt thông minh, tỷ lệ tấn công thành công là 0%; trong thử nghiệm chèn từ khóa chung Gray Swan, sau 15 lần cố gắng, tỷ lệ thành công giảm từ 5,5% của Opus 4.8 xuống còn 2,0%. Tỷ lệ thành công bằng không chỉ đạt được khi các sản phẩm như Claude Cowork bật Chế độ Tự động, chế độ này kết hợp hai lớp phòng thủ bao gồm quét đầu vào và chặn thực thi.","category":"模型更新","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic cho biết Opus 5 gần như miễn dịch với việc tiêm từ khóa trình duyệt, tỷ lệ tấn công thành công giảm xuống bằng không - Tin tức AI Aioga","description":"Anthropic cho biết mô hình Opus 5 của họ gần như miễn nhiễm với các cuộc tấn công chèn từ khóa trong phần mềm riêng của họ. Trong 129 kịch bản thử nghiệm trình duyệt thông minh, tỷ...","url":"https://www.aioga.com/vi/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:46:28.647Z"},"id":{"title":"Anthropic menyatakan Opus 5 hampir kebal terhadap injeksi prompt browser, tingkat keberhasilan serangan turun menjadi nol","summary":"Anthropic menyatakan bahwa model Opus 5 mereka hampir kebal terhadap serangan penyisipan prompt di perangkat lunak mereka sendiri. Dalam 129 skenario pengujian agen peramban pintar, tingkat keberhasilan serangan adalah nol; dalam pengujian penyisipan prompt umum Gray Swan, tingkat keberhasilan setelah 15 percobaan turun dari 5,5% pada Opus 4.8 menjadi 2,0%. Tingkat keberhasilan nol hanya tercapai ketika produk seperti Claude Cowork mengaktifkan Mode Otomatis, yang menambahkan dua lapisan pertahanan yakni pemindaian input dan pemblokiran eksekusi.","category":"模型更新","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic menyatakan Opus 5 hampir kebal terhadap injeksi prompt browser, tingkat keberhasilan serangan turun menjadi nol - Berita AI Aioga","description":"Anthropic menyatakan bahwa model Opus 5 mereka hampir kebal terhadap serangan penyisipan prompt di perangkat lunak mereka sendiri. Dalam 129 skenario pengujian agen peramban pintar...","url":"https://www.aioga.com/id/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:47:09.556Z"},"th":{"title":"Anthropic กล่าวว่า Opus 5 แทบจะมีภูมิคุ้มกันต่อการโจมตีด้วยพรอมต์ในเบราว์เซอร์ อัตราการโจมตีสำเร็จลดลงเหลือศูนย์","summary":"Anthropic กล่าวว่าโมเดล Opus 5 ของตนแทบจะทนต่อการโจมตีด้วยการฝังคำสั่งในซอฟต์แวร์ของตนเอง ในการทดสอบ 129 สถานการณ์ของตัวแทนเบราว์เซอร์ อัตราความสำเร็จในการโจมตีคือศูนย์; ในการทดสอบการฝังคำสั่งทั่วไปของ Gray Swan หลังจากลอง 15 ครั้ง อัตราความสำเร็จลดลงจาก 5.5% ของ Opus 4.8 เหลือ 2.0% อัตราความสำเร็จเป็นศูนย์เกิดขึ้นเฉพาะเมื่อเปิดใช้งานโหมดอัตโนมัติ (Auto Mode) ในผลิตภัณฑ์อย่าง Claude Cowork ซึ่งโหมดนี้รวมการสแกนข้อมูลเข้าและการป้องกันการดำเนินการซ้อนกันสองชั้น","category":"模型更新","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic กล่าวว่า Opus 5 แทบจะมีภูมิคุ้มกันต่อการโจมตีด้วยพรอมต์ในเบราว์เซอร์ อัตราการโจมตีสำเร็จลดลงเหลือศูนย์ - ข่าว AI Aioga","description":"Anthropic กล่าวว่าโมเดล Opus 5 ของตนแทบจะทนต่อการโจมตีด้วยการฝังคำสั่งในซอฟต์แวร์ของตนเอง ในการทดสอบ 129 สถานการณ์ของตัวแทนเบราว์เซอร์ อัตราความสำเร็จในการโจมตีคือศูนย์; ในการทดสอบ...","url":"https://www.aioga.com/th/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:47:15.180Z"},"pl":{"title":"Anthropic twierdzi, że Opus 5 jest prawie odporny na wstrzykiwanie promptów w przeglądarce, a skuteczność ataków spadła do zera","summary":"Anthropic twierdzi, że jego model Opus 5 jest w swoich własnych programach prawie odporny na ataki typu prompt injection. W 129 scenariuszach testowych dla inteligentnych agentów przeglądarki wskaźnik skuteczności ataków wyniósł zero; w uniwersalnym teście prompt injection Gray Swan, po 15 próbach wskaźnik skuteczności spadł z 5,5% w Opus 4.8 do 2,0%. Zerowy wskaźnik skuteczności osiągnięto tylko w produktach takich jak Claude Cowork, gdy włączono Tryb Auto, który łączy dwie warstwy obrony: skanowanie wejścia i blokadę wykonywania.","category":"模型更新","source":"The Decoder：AI News（RSS）","aggregationSource":"The Decoder：AI News（RSS）","pageTitle":"Anthropic twierdzi, że Opus 5 jest prawie odporny na wstrzykiwanie promptów w przeglądarce, a skuteczność ataków spadła do zera - Aioga Wiadomości AI","description":"Anthropic twierdzi, że jego model Opus 5 jest w swoich własnych programach prawie odporny na ataki typu prompt injection. W 129 scenariuszach testowych dla inteligentnych agentów p...","url":"https://www.aioga.com/pl/news/cms0942e500corodza9v7s7sb/","contentTranslated":true,"sourceHash":"eeb134534a7de919","translatedAt":"2026-07-26T09:48:00.231Z"}}}}