{"id":61316,"date":"2026-08-28T20:50:15","date_gmt":"2026-08-28T20:50:15","guid":{"rendered":"https:\/\/www.theregister.com\/a\/5293372"},"modified":"2026-08-28T20:50:15","modified_gmt":"2026-08-28T20:50:15","slug":"researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/","title":{"rendered":"Researcher shows how Claude Code can be tricked simply by asking it to summarize a website"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/5222549.jpg?imageId=5222549&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" class=\"ff-og-image-inserted\"><\/div>\n<div data-element-guid=\"d11159dd-82a3-4c53-901c-d41dec75505c\" readability=\"31.174468085106\">\n<p class=\"kicker \">security<\/p>\n<p class=\"subtitle \">More prompt-injection hijinks from&nbsp;wunderwuzzi<\/p>\n<\/p><\/div>\n<div data-element-guid=\"4c9dc5d9-c886-4348-bf4a-01d0dc71377d\" readability=\"126.45159010601\"> <!-- placeholder(#1) --><\/p>\n<div data-element-guid=\"0fb02ed4-4174-4be5-bd5f-2eccad375723\" id=\"toplist_5293374\" class=\"column toplist desktop-floatRight mobile-floatRight layout_vertical small-12 large-3 small-abs-12 large-abs-3\">\n<div class=\"content\">\n<h3 class=\"headline t21 font-weight-bold m-font-weight-bold bg-primary color_mobile_bg-primary align-center mobile_text_align_align-center font-RobotoMono hasTextPadding mobile-hasTextPadding\"> MOST POPULAR <\/h3>\n<\/p><\/div>\n<\/div>\n<p>Anthropic\u2019s Claude Code running Opus 5 in Auto Mode can be tricked into executing attacker-controlled code simply by asking the coding agent to summarize a website. The attack works up to 80 percent of the time, according to&nbsp;<a href=\"https:\/\/www.theregister.com\/special-features\/2025\/10\/30\/anthropics-claude-convinced-to-exfiltrate-private-data\/1109039\" rel=\"nofollow\">prompt-injection wizard<\/a> Johann Rehberger, aka wunderwuzzi.<\/p>\n<p>In a <a href=\"https:\/\/embracethered.com\/blog\/posts\/2026\/breaking-claude-code-opus-5-and-automode\/\" rel=\"nofollow\">blog<\/a> and <a href=\"https:\/\/youtu.be\/18PIeJoxYtc?si=1g-E31JGHQKDn0Ox\" rel=\"nofollow\">video demo<\/a>, he detailed how to hijack Opus 5 in Auto Mode, which is the default setting for Claude as of mid-August.<\/p>\n<p>It starts off by asking the agentic coding model to summarize a malicious website that presents itself as an archive of notebook records, and then tricking Claude into using curl instead of its WebFetch tool to retrieve the contents of the page \u2013 but without directly telling the model to use curl.<\/p>\n<p>The WebFetch request fails, returning a 415 Unsupported Media Type response, so the model decides to access the website directly by issuing a Bash tool call with curl.&nbsp;<\/p>\n<p>The website returns a 303 response, and redirects to a malicious ZIP archive, which Claude then downloads. This archive contains seemingly harmless files including catalog metadata, a README file, seven Base85\/zlib-encoded JSON notebook records, a macOS decoder-darwin binary \u2013 plus a poisoned Python file named <span class=\"font-RobotoMono \" data-lab-fontface=\"RobotoMono\">struct.py<\/span>.<\/p>\n<p>Claude, per its safety guardrails, refuses to run the decoder: \u201cThis is planned and what the attacker wants,\u201d Rehberger wrote. Instead of using the supplied binary, the AI decides to write its own decoder. \u201cIronically, that safety decision is the exploit path,\u201d Rehberger explained, adding a purple devil emoji to the text.<\/p>\n<p>The new decoder imports <span class=\"font-RobotoMono \" data-lab-fontface=\"RobotoMono\">base64<\/span>, and from here the attack relies on <a href=\"https:\/\/stackoverflow.com\/questions\/491705\/python-problem-with-local-modules-shadowing-global-modules\" rel=\"nofollow\">Python module shadowing<\/a> to trick the model into running the malicious <span class=\"font-RobotoMono \" data-lab-fontface=\"RobotoMono\">struct.py<\/span> code.<\/p>\n<p>Module shadowing occurs when a local file shares the same name as a Python standard-library module. The local file hides the official module, causing Python to load it instead.<\/p>\n<p>In this case, the standard-library base64 module imports the legitimate struct module, and the malicious ZIP contains a malicious file with the same name.&nbsp;<\/p>\n<p>Rehberger says he used ChatGPT to obfuscate the malicious <span class=\"font-RobotoMono \" data-lab-fontface=\"RobotoMono\">struct.py<\/span> code to bypass Claude\u2019s safety controls, and this successfully launches a separate Python process to download and execute a remote payload \u2013 in this case a command-and-control callback, which in turn opens Calculator. We assume that real attackers would execute something a little more nefarious.<\/p>\n<p>In another attack scenario, <span class=\"font-RobotoMono \" data-lab-fontface=\"RobotoMono\">struct.py<\/span> launches a second, headless Claude Code via <span class=\"font-RobotoMono \" data-lab-fontface=\"RobotoMono\">claude -p<\/span>, meaning this prompt injection can be used not just to remotely execute code, but rather to create a whole new agent.<\/p>\n<p>\u201cThe nested Claude gets its own tool access and context,\u201d Rehberger wrote. \u201cIn these runs the child performed basic recon (whoami, uname, id), opened Calculator and wrote to local files in the home folder.\u201d<\/p>\n<p>Across three variants tested five times each, which Rehberger noted were small samples, he reported success rates between 60 percent and 80 percent. \u201cI would say that these results are representative for a motivated attack, but not comprehensive.\u201d<\/p>\n<p>Anthropic did not respond to <span class=\"italic m-italic \" data-lab-italic=\"italic\">The Register<\/span>\u2019s request for comment, but reportedly told Rehberger that the model\u2019s \u201cbehavior is working as designed.\u201d We\u2019ve <a href=\"https:\/\/www.theregister.com\/security\/2026\/04\/19\/ai-vendors-response-to-security-flaws-it-wasnt-me\/5228722\">heard this one before<\/a>.<\/p>\n<p>\u201cAuto Mode is a convenience feature backed by a best-effort classifier, not a security guarantee,\u201d Rehberger wrote, paraphrasing Anthropic\u2019s response to his security report.&nbsp;<\/p>\n<p>According to Rehberger, the classifier isn\u2019t built to stop determined prompt-injection chains made up of individually benign-looking steps, and the real boundary is OS isolation and network egress control.<\/p>\n<p>The key takeaway, according to Rehberger, is to run this and other coding agents in a sandbox. <\/p>\n<p>\u201cThe solution is something we talked about for many years,\u201d he wrote. \u201cDo not trust the model output.\u201d\u00ae<\/p>\n<\/p><\/div>\n<p><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/?imageId=5222549&#038;width=800\">READ MORE <a href=\"https:\/\/www.theregister.com\/research\/2026\/08\/28\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/5293372\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> More prompt-injection hijinks from wunderwuzzi READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[842],"class_list":["post-61316","post","type-post","status-publish","format-standard","hentry","category-the-register","tag-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Researcher shows how Claude Code can be tricked simply by asking it to summarize a website 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Researcher shows how Claude Code can be tricked simply by asking it to summarize a website 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-28T20:50:15+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/image.theregister.com\/5222549.jpg?imageId=5222549&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Researcher shows how Claude Code can be tricked simply by asking it to summarize a website\",\"datePublished\":\"2026-08-28T20:50:15+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\\\/\"},\"wordCount\":637,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/image.theregister.com\\\/5222549.jpg?imageId=5222549&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"keywords\":[\"Research\"],\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\\\/\",\"name\":\"Researcher shows how Claude Code can be tricked simply by asking it to summarize a website 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/image.theregister.com\\\/5222549.jpg?imageId=5222549&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"datePublished\":\"2026-08-28T20:50:15+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\\\/#primaryimage\",\"url\":\"https:\\\/\\\/image.theregister.com\\\/5222549.jpg?imageId=5222549&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"contentUrl\":\"https:\\\/\\\/image.theregister.com\\\/5222549.jpg?imageId=5222549&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Research\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/research\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Researcher shows how Claude Code can be tricked simply by asking it to summarize a website\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Researcher shows how Claude Code can be tricked simply by asking it to summarize a website 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/","og_locale":"en_US","og_type":"article","og_title":"Researcher shows how Claude Code can be tricked simply by asking it to summarize a website 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-08-28T20:50:15+00:00","og_image":[{"url":"https:\/\/image.theregister.com\/5222549.jpg?imageId=5222549&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Researcher shows how Claude Code can be tricked simply by asking it to summarize a website","datePublished":"2026-08-28T20:50:15+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/"},"wordCount":637,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/#primaryimage"},"thumbnailUrl":"https:\/\/image.theregister.com\/5222549.jpg?imageId=5222549&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","keywords":["Research"],"articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/","url":"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/","name":"Researcher shows how Claude Code can be tricked simply by asking it to summarize a website 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/#primaryimage"},"thumbnailUrl":"https:\/\/image.theregister.com\/5222549.jpg?imageId=5222549&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","datePublished":"2026-08-28T20:50:15+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/#primaryimage","url":"https:\/\/image.theregister.com\/5222549.jpg?imageId=5222549&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","contentUrl":"https:\/\/image.theregister.com\/5222549.jpg?imageId=5222549&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/researcher-shows-how-claude-code-can-be-tricked-simply-by-asking-it-to-summarize-a-website\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Research","item":"https:\/\/www.threatshub.org\/blog\/tag\/research\/"},{"@type":"ListItem","position":3,"name":"Researcher shows how Claude Code can be tricked simply by asking it to summarize a website"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61316","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=61316"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61316\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=61316"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=61316"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=61316"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}