Advertisement
Autonomous AI Agents Email Security Insights on Perimeter Defences
An autonomous AI agent emailed security researcher Bruce Schneier detailing perimeter defences, anti-bot mechanisms, and invisible prompt injections.
The Agentic SOC: From AI Theater to Real Defense
Explore the Agentic SOC transition, focusing on measurable AI ROI, new risks like indirect prompt injection, and redefining analyst roles for autonomous defense.
AI Email Summarizers Vulnerable to Hidden HTML Prompts
Attackers can use invisible HTML prompts to manipulate AI email summarizers, generating false information and potential security risks.
Alice Secures $140M to Enhance AI Model Defenses and Guardrails
AI security firm Alice raised $140M to combat adversarial AI, prompt injection, and jailbreak attempts in generative AI systems.
Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
Researchers discover cryptographic context injection, a novel technique bypassing AI safety filters in xAI Grok and Google Gemini using encryption.
Cryptographic Context Injection Exposes Grok Chat Data
Adversa AI reveals Cryptographic Context Injection, allowing web pages to steal Grok user data and chat prompts without user consent.
Advertisement
CVE-2026-24301: CoSnitch Exploits Microsoft Copilot Personal
Varonis disclosed CoSnitch (CVE-2026-24301), affecting Microsoft Copilot Personal, enabling one-click data exfiltration and persistent memory poisoning.
AI 'Mind Viruses' Spread via Persistent Prompt Files
Security research reveals self-propagating AI 'mind viruses' can spread between autonomous agents through editable system prompt files.
Context Bombing: Defending Against AI Hacking Agents
Researchers at Tracebit introduce 'context bombing,' a defensive prompt injection technique to shut down AI hacking agents by exploiting guardrails.
Anthropic Opus 5 Significantly Boosts Prompt Injection Resistance
Anthropic's Opus 5 demonstrates superior resistance to prompt injection attacks on the IPI benchmark, outperforming other leading LLMs, including GPT-5.6 variants.
Claude Mythos: Securing LLMs in Enterprise — Hype vs. Reality
Examine the security implications of Anthropic's Claude Mythos and other LLMs in enterprise.
Persistent Prompt Injection Risks in Microsoft 365 Copilot for Word
Researchers demonstrate how hidden instructions in Word documents can persist through Microsoft 365 Copilot drafting, creating risks of malicious prompt propagation.
PLC Exploits and AI Prompt Injection: Analysis of Emerging Threats
Analysis of recent threats including PLC attacks, AI image prompt injection, and Android spyware disguised as utility applications in the latest bulletin.
AWS Kiro RCE via Indirect Prompt Injection - Mitigation Guide
Research reveals a critical flaw in AWS Kiro where malicious web pages trigger RCE by rewriting configuration files via indirect prompt injection attacks.
Open-Source Android AI Agent Hijacking Leads to Host System RCE
Learn how invisible text exploits open-source Android AI agents to trigger malicious code execution on host PCs via indirect prompt injection.
OpenAI GPT-Red: Automating Prompt Injection Discovery for GPT-5.6 Sol
OpenAI reveals GPT-Red, an automated red-teaming model designed to detect prompt injection vulnerabilities and harden GPT-5.6 Sol via adversarial training.
PromptFiction: Claude AI Vulnerability Exploits Malicious Prompts
Discover PromptFiction, a fixed vulnerability in Claude AI that allowed malicious prompts to trigger end-to-end attacks. Learn mitigation for AI agent security.
MemGhost Attack: Persistent Memory Poisoning in AI Agents via Email
The MemGhost attack targets AI agent memory systems via email, planting persistent false facts to stealthily manipulate long-term assistant behavior.
Ghostcommit: Hidden Prompt Injection in Images Targets AI Agents
Researchers demonstrate Ghostcommit, a technique using images to hide prompt injection attacks that trick AI agents into exfiltrating repository secrets.
How Agentjacking Exploits AI Coding Agents via Fake Bug Reports
Researchers demonstrate 'Agentjacking,' a technique using indirect prompt injection to hijack AI coding agents through malicious GitHub bug reports.
AI Agents Vulnerable to Data Leak via Poisoned MCP Tools
Microsoft warns that malicious tool descriptions for AI agents can lead to stealthy data exfiltration, bypassing security controls by mimicking routine actions.
Claude Code Indirect Prompt Injection: Hijacking Developer Machines
Researchers demonstrate a new attack method leveraging indirect prompt injection in Claude Code, enabling the hijack of developer machines via malicious code in…
LLM Prompt Injection: Role Confusion Exposes Core Architectural Flaws
An in-depth analysis of LLM prompt injection, detailing how 'role confusion' in model representations undermines tag-based security and demands architectural solutions.
Gaslight macOS Malware Uses Prompt Injection to Bypass AI Detection
Gaslight is a newly discovered Rust-based macOS implant that uses prompt injection to deceive AI-driven analysis tools and bypass automated detection.