Advertisement

AI Agents Vulnerable to Data Leak via Poisoned MCP Tools
Microsoft warns that malicious tool descriptions for AI agents can lead to stealthy data exfiltration, bypassing security controls by mimicking routine actions.
Claude Code Indirect Prompt Injection: Hijacking Developer Machines
Researchers demonstrate a new attack method leveraging indirect prompt injection in Claude Code, enabling the hijack of developer machines via malicious code in
LLM Prompt Injection: Role Confusion Exposes Core Architectural Flaws
An in-depth analysis of LLM prompt injection, detailing how 'role confusion' in model representations undermines tag-based security and demands architectural solutions.

Microsoft Copilot 'SearchLeak' Attack: AI Prompt Injection Data Theft
Analysis of the critical Microsoft Copilot 'SearchLeak' attack. Learn how prompt injection allowed 1-click data theft and crucial defense strategies for AI applications.

OpenAI ChatGPT Lockdown Mode: Mitigating Prompt Injection Exfiltration
OpenAI introduces ChatGPT Lockdown Mode for personal accounts to prevent prompt injection attacks from exfiltrating sensitive data via external tools.

Google Gemini Indirect Prompt Injection via Malicious Notifications
Security researchers demonstrate how malicious notifications can manipulate Google Gemini's voice assistant to perform unauthorized tasks or exfiltrate data.

ChatGPT ChatGPhish Vulnerability: Web Summaries Lead to Phishing
A newly disclosed ChatGPhish vulnerability allows attackers to leverage ChatGPT's Markdown trust for prompt injections and sophisticated phishing campaigns.
Claude Code Sandbox Bypass: Anthropic Patches CLI Vulnerability
Anthropic recently addressed a sandbox bypass in Claude Code. This vulnerability could have allowed data exfiltration when combined with prompt injection.
_NicoElNino_Alamy.png?width=1280&auto=webp&quality=80&disable=upscale)
Google Antigravity RCE via Prompt Injection — Mitigation Guide
Google patched a critical RCE flaw in its AI-based Antigravity tool, stemming from a prompt injection vulnerability allowing sandbox escape and arbitrary code execution.

Microsoft and Salesforce Patch Prompt Injection Flaws in AI Agents
Researchers identified prompt injection vulnerabilities in Microsoft Copilot and Salesforce Agentforce that could allow attackers to exfiltrate sensitive data.
Securing AI Agents: Threats & Defenses with Falcon AIDR, NeMo Guardrails
Explore threats to AI agents like prompt injection and data poisoning. Learn how CrowdStrike Falcon AIDR and NVIDIA NeMo Guardrails defend against AI-specific attacks.

Claudy Day: Prompt Injection and XSS Flaws Target Claude AI Users
Researchers uncover 'Claudy Day', a trio of vulnerabilities in Anthropic's Claude AI that allow data theft through malicious Google search results.