<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Prompt Injection</title><description>Cybersecurity articles tagged #Prompt Injection on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Autonomous AI Agents Email Security Insights on Perimeter Defences</title><link>https://runtimerebel.com/blog/autonomous-ai-agents-email-security-insights-on-perimeter-defences</link><guid isPermaLink="true">https://runtimerebel.com/blog/autonomous-ai-agents-email-security-insights-on-perimeter-defences</guid><description>An autonomous AI agent emailed security researcher Bruce Schneier detailing perimeter defences, anti-bot mechanisms, and invisible prompt injections.</description><pubDate>Wed, 02 Sep 2026 19:09:10 GMT</pubDate><category>Artificial Intelligence</category><category>Prompt Injection</category><category>Bot Management</category><category>Email Security</category></item><item><title>The Agentic SOC: From AI Theater to Real Defense</title><link>https://runtimerebel.com/blog/the-agentic-soc-from-ai-theater-to-real-defense</link><guid isPermaLink="true">https://runtimerebel.com/blog/the-agentic-soc-from-ai-theater-to-real-defense</guid><description>Explore the Agentic SOC transition, focusing on measurable AI ROI, new risks like indirect prompt injection, and redefining analyst roles for autonomous defense.</description><pubDate>Tue, 01 Sep 2026 19:03:18 GMT</pubDate><category>AI in Security</category><category>SOC Operations</category><category>Prompt Injection</category><category>Automation</category><category>Threat Intelligence</category></item><item><title>AI Email Summarizers Vulnerable to Hidden HTML Prompts</title><link>https://runtimerebel.com/blog/ai-email-summarizers-vulnerable-to-hidden-html-prompts</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-email-summarizers-vulnerable-to-hidden-html-prompts</guid><description>Attackers can use invisible HTML prompts to manipulate AI email summarizers, generating false information and potential security risks.</description><pubDate>Wed, 26 Aug 2026 00:44:15 GMT</pubDate><category>AI</category><category>Prompt Injection</category><category>Email Security</category><category>Social Engineering</category><category>Hidden HTML</category></item><item><title>Alice Secures $140M to Enhance AI Model Defenses and Guardrails</title><link>https://runtimerebel.com/blog/alice-secures-140m-to-enhance-ai-model-defenses-and-guardrails</link><guid isPermaLink="true">https://runtimerebel.com/blog/alice-secures-140m-to-enhance-ai-model-defenses-and-guardrails</guid><description>AI security firm Alice raised $140M to combat adversarial AI, prompt injection, and jailbreak attempts in generative AI systems.</description><pubDate>Wed, 26 Aug 2026 00:43:29 GMT</pubDate><category>AI Security</category><category>Adversarial AI</category><category>Prompt Injection</category><category>Generative AI</category><category>Funding</category></item><item><title>Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini</title><link>https://runtimerebel.com/blog/encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini</link><guid isPermaLink="true">https://runtimerebel.com/blog/encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini</guid><description>Researchers discover cryptographic context injection, a novel technique bypassing AI safety filters in xAI Grok and Google Gemini using encryption.</description><pubDate>Sat, 22 Aug 2026 08:19:25 GMT</pubDate><category>Artificial Intelligence</category><category>Prompt Injection</category><category>Zero-Day</category><category>Data Breach</category><category>Google Gemini</category></item><item><title>Cryptographic Context Injection Exposes Grok Chat Data</title><link>https://runtimerebel.com/blog/cryptographic-context-injection-exposes-grok-chat-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/cryptographic-context-injection-exposes-grok-chat-data</guid><description>Adversa AI reveals Cryptographic Context Injection, allowing web pages to steal Grok user data and chat prompts without user consent.</description><pubDate>Thu, 20 Aug 2026 16:23:24 GMT</pubDate><category>Xai</category><category>Adversa AI</category><category>Prompt Injection</category><category>Data Exfiltration</category><category>Grok</category></item><item><title>CVE-2026-24301: CoSnitch Exploits Microsoft Copilot Personal</title><link>https://runtimerebel.com/blog/cve-2026-24301-cosnitch-exploits-microsoft-copilot-personal</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-24301-cosnitch-exploits-microsoft-copilot-personal</guid><description>Varonis disclosed CoSnitch (CVE-2026-24301), affecting Microsoft Copilot Personal, enabling one-click data exfiltration and persistent memory poisoning.</description><pubDate>Wed, 19 Aug 2026 00:39:19 GMT</pubDate><category>Data Exfiltration</category><category>Prompt Injection</category><category>CVE-2026-24301</category><category>Microsoft Copilot Personal</category><category>Memory Poisoning</category></item><item><title>AI &apos;Mind Viruses&apos; Spread via Persistent Prompt Files</title><link>https://runtimerebel.com/blog/ai-mind-viruses-spread-via-persistent-prompt-files</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-mind-viruses-spread-via-persistent-prompt-files</guid><description>Security research reveals self-propagating AI &apos;mind viruses&apos; can spread between autonomous agents through editable system prompt files.</description><pubDate>Tue, 18 Aug 2026 16:19:59 GMT</pubDate><category>AI</category><category>Large Language Models</category><category>Prompt Injection</category><category>Anthropic</category><category>Autonomous Agents</category></item><item><title>Context Bombing: Defending Against AI Hacking Agents</title><link>https://runtimerebel.com/blog/context-bombing-defending-against-ai-hacking-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/context-bombing-defending-against-ai-hacking-agents</guid><description>Researchers at Tracebit introduce &apos;context bombing,&apos; a defensive prompt injection technique to shut down AI hacking agents by exploiting guardrails.</description><pubDate>Wed, 12 Aug 2026 16:50:19 GMT</pubDate><category>AI Security</category><category>Prompt Injection</category><category>Large Language Models</category><category>AWS Security</category><category>Tracebit</category></item><item><title>Anthropic Opus 5 Significantly Boosts Prompt Injection Resistance</title><link>https://runtimerebel.com/blog/anthropic-opus-5-significantly-boosts-prompt-injection-resistance</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-opus-5-significantly-boosts-prompt-injection-resistance</guid><description>Anthropic&apos;s Opus 5 demonstrates superior resistance to prompt injection attacks on the IPI benchmark, outperforming other leading LLMs, including GPT-5.6 variants.</description><pubDate>Sat, 01 Aug 2026 10:01:46 GMT</pubDate><category>Anthropic Opus 5</category><category>Prompt Injection</category><category>LLM Security</category><category>IPI Benchmark</category><category>AI Security</category></item><item><title>Claude Mythos: Securing LLMs in Enterprise — Hype vs. Reality</title><link>https://runtimerebel.com/blog/claude-mythos-securing-llms-in-enterprise-hype-vs-reality</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-mythos-securing-llms-in-enterprise-hype-vs-reality</guid><description>Examine the security implications of Anthropic&apos;s Claude Mythos and other LLMs in enterprise.</description><pubDate>Thu, 30 Jul 2026 17:32:21 GMT</pubDate><category>Claude Mythos</category><category>Anthropic</category><category>Large Language Models</category><category>LLM Security</category><category>Prompt Injection</category><category>AI Governance</category><category>Enterprise AI</category></item><item><title>Persistent Prompt Injection Risks in Microsoft 365 Copilot for Word</title><link>https://runtimerebel.com/blog/persistent-prompt-injection-risks-in-microsoft-365-copilot-for-word</link><guid isPermaLink="true">https://runtimerebel.com/blog/persistent-prompt-injection-risks-in-microsoft-365-copilot-for-word</guid><description>Researchers demonstrate how hidden instructions in Word documents can persist through Microsoft 365 Copilot drafting, creating risks of malicious prompt propagation.</description><pubDate>Thu, 30 Jul 2026 14:05:35 GMT</pubDate><category>Microsoft 365</category><category>Copilot</category><category>Prompt Injection</category><category>AI Security</category><category>Document Security</category></item><item><title>PLC Exploits and AI Prompt Injection: Analysis of Emerging Threats</title><link>https://runtimerebel.com/blog/plc-exploits-and-ai-prompt-injection-analysis-of-emerging-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/plc-exploits-and-ai-prompt-injection-analysis-of-emerging-threats</guid><description>Analysis of recent threats including PLC attacks, AI image prompt injection, and Android spyware disguised as utility applications in the latest bulletin.</description><pubDate>Thu, 23 Jul 2026 17:26:37 GMT</pubDate><category>PLC Security</category><category>AI Security</category><category>Android Spyware</category><category>Prompt Injection</category><category>ICS Security</category></item><item><title>AWS Kiro RCE via Indirect Prompt Injection - Mitigation Guide</title><link>https://runtimerebel.com/blog/aws-kiro-rce-via-indirect-prompt-injection-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/aws-kiro-rce-via-indirect-prompt-injection-mitigation-guide</guid><description>Research reveals a critical flaw in AWS Kiro where malicious web pages trigger RCE by rewriting configuration files via indirect prompt injection attacks.</description><pubDate>Tue, 21 Jul 2026 17:22:23 GMT</pubDate><category>AWS</category><category>Kiro</category><category>RCE</category><category>Prompt Injection</category><category>AI Security</category></item><item><title>Open-Source Android AI Agent Hijacking Leads to Host System RCE</title><link>https://runtimerebel.com/blog/open-source-android-ai-agent-hijacking-leads-to-host-system-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/open-source-android-ai-agent-hijacking-leads-to-host-system-rce</guid><description>Learn how invisible text exploits open-source Android AI agents to trigger malicious code execution on host PCs via indirect prompt injection.</description><pubDate>Tue, 21 Jul 2026 13:54:29 GMT</pubDate><category>Android Security</category><category>AI Agents</category><category>Prompt Injection</category><category>RCE</category><category>Mobile Security</category><category>Appagent</category></item><item><title>OpenAI GPT-Red: Automating Prompt Injection Discovery for GPT-5.6 Sol</title><link>https://runtimerebel.com/blog/openai-gpt-red-automating-prompt-injection-discovery-for-gpt-5-6-sol</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-gpt-red-automating-prompt-injection-discovery-for-gpt-5-6-sol</guid><description>OpenAI reveals GPT-Red, an automated red-teaming model designed to detect prompt injection vulnerabilities and harden GPT-5.6 Sol via adversarial training.</description><pubDate>Thu, 16 Jul 2026 10:10:18 GMT</pubDate><category>OpenAI</category><category>GPT Red</category><category>GPT 5 6 Sol</category><category>Prompt Injection</category><category>Adversarial Training</category></item><item><title>PromptFiction: Claude AI Vulnerability Exploits Malicious Prompts</title><link>https://runtimerebel.com/blog/promptfiction-claude-ai-vulnerability-exploits-malicious-prompts</link><guid isPermaLink="true">https://runtimerebel.com/blog/promptfiction-claude-ai-vulnerability-exploits-malicious-prompts</guid><description>Discover PromptFiction, a fixed vulnerability in Claude AI that allowed malicious prompts to trigger end-to-end attacks. Learn mitigation for AI agent security.</description><pubDate>Wed, 15 Jul 2026 17:22:45 GMT</pubDate><category>PromptFiction</category><category>Claude AI</category><category>AI Security</category><category>Prompt Injection</category><category>Vulnerability</category></item><item><title>MemGhost Attack: Persistent Memory Poisoning in AI Agents via Email</title><link>https://runtimerebel.com/blog/memghost-attack-persistent-memory-poisoning-in-ai-agents-via-email</link><guid isPermaLink="true">https://runtimerebel.com/blog/memghost-attack-persistent-memory-poisoning-in-ai-agents-via-email</guid><description>The MemGhost attack targets AI agent memory systems via email, planting persistent false facts to stealthily manipulate long-term assistant behavior.</description><pubDate>Mon, 13 Jul 2026 17:59:10 GMT</pubDate><category>MemGhost</category><category>AI Security</category><category>Prompt Injection</category><category>LLM Agents</category><category>Adversarial ML</category></item><item><title>Ghostcommit: Hidden Prompt Injection in Images Targets AI Agents</title><link>https://runtimerebel.com/blog/ghostcommit-hidden-prompt-injection-in-images-targets-ai-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/ghostcommit-hidden-prompt-injection-in-images-targets-ai-agents</guid><description>Researchers demonstrate Ghostcommit, a technique using images to hide prompt injection attacks that trick AI agents into exfiltrating repository secrets.</description><pubDate>Sat, 11 Jul 2026 09:39:43 GMT</pubDate><category>Ghostcommit</category><category>Prompt Injection</category><category>Steganography</category><category>AI Security</category><category>Coderabbit</category><category>Bugbot</category></item><item><title>How Agentjacking Exploits AI Coding Agents via Fake Bug Reports</title><link>https://runtimerebel.com/blog/how-agentjacking-exploits-ai-coding-agents-via-fake-bug-reports</link><guid isPermaLink="true">https://runtimerebel.com/blog/how-agentjacking-exploits-ai-coding-agents-via-fake-bug-reports</guid><description>Researchers demonstrate &apos;Agentjacking,&apos; a technique using indirect prompt injection to hijack AI coding agents through malicious GitHub bug reports.</description><pubDate>Wed, 01 Jul 2026 09:21:10 GMT</pubDate><category>Agentjacking</category><category>Prompt Injection</category><category>AI Security</category><category>Trail of Bits</category><category>Opendevin</category><category>Supply Chain Security</category></item><item><title>AI Agents Vulnerable to Data Leak via Poisoned MCP Tools</title><link>https://runtimerebel.com/blog/ai-agents-vulnerable-to-data-leak-via-poisoned-mcp-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-vulnerable-to-data-leak-via-poisoned-mcp-tools</guid><description>Microsoft warns that malicious tool descriptions for AI agents can lead to stealthy data exfiltration, bypassing security controls by mimicking routine actions.</description><pubDate>Wed, 01 Jul 2026 01:02:51 GMT</pubDate><category>AI Agents</category><category>Data Exfiltration</category><category>Supply Chain Attack</category><category>Microsoft</category><category>Prompt Injection</category></item><item><title>Claude Code Indirect Prompt Injection: Hijacking Developer Machines</title><link>https://runtimerebel.com/blog/claude-code-indirect-prompt-injection-hijacking-developer-machines</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-code-indirect-prompt-injection-hijacking-developer-machines</guid><description>Researchers demonstrate a new attack method leveraging indirect prompt injection in Claude Code, enabling the hijack of developer machines via malicious code in…</description><pubDate>Mon, 29 Jun 2026 17:07:49 GMT</pubDate><category>Claude Code</category><category>Prompt Injection</category><category>Supply Chain Attack</category><category>Developer Security</category><category>AI Security</category><category>Reverse Shell</category><category>Machine Hijack</category></item><item><title>LLM Prompt Injection: Role Confusion Exposes Core Architectural Flaws</title><link>https://runtimerebel.com/blog/llm-prompt-injection-role-confusion-exposes-core-architectural-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/llm-prompt-injection-role-confusion-exposes-core-architectural-flaws</guid><description>An in-depth analysis of LLM prompt injection, detailing how &apos;role confusion&apos; in model representations undermines tag-based security and demands architectural solutions.</description><pubDate>Thu, 25 Jun 2026 13:06:12 GMT</pubDate><category>Prompt Injection</category><category>LLM Security</category><category>AI Security</category><category>Role Confusion</category><category>Large Language Models</category></item><item><title>Gaslight macOS Malware Uses Prompt Injection to Bypass AI Detection</title><link>https://runtimerebel.com/blog/gaslight-macos-malware-uses-prompt-injection-to-bypass-ai-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/gaslight-macos-malware-uses-prompt-injection-to-bypass-ai-detection</guid><description>Gaslight is a newly discovered Rust-based macOS implant that uses prompt injection to deceive AI-driven analysis tools and bypass automated detection.</description><pubDate>Thu, 25 Jun 2026 13:01:04 GMT</pubDate><category>Gaslight Malware</category><category>macOS Security</category><category>Prompt Injection</category><category>Anti Analysis</category><category>Rust Malware</category></item><item><title>AI Agent Traps: Information as an Attack Surface for Autonomous Systems</title><link>https://runtimerebel.com/blog/ai-agent-traps-information-as-an-attack-surface-for-autonomous-systems</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agent-traps-information-as-an-attack-surface-for-autonomous-systems</guid><description>Attackers exploit trusted data sources to deploy AI agent traps, leading to hidden content injections and cognitive state poisoning for autonomous AI systems.</description><pubDate>Thu, 25 Jun 2026 00:59:45 GMT</pubDate><category>AI Security</category><category>AI Agent Traps</category><category>Data Poisoning</category><category>Large Language Models</category><category>Autonomous AI</category><category>Attack Surface</category><category>Prompt Injection</category></item><item><title>Bypass AI Malware Scanners via Policy-Triggering Prompt Injection</title><link>https://runtimerebel.com/blog/bypass-ai-malware-scanners-via-policy-triggering-prompt-injection</link><guid isPermaLink="true">https://runtimerebel.com/blog/bypass-ai-malware-scanners-via-policy-triggering-prompt-injection</guid><description>Malware authors are embedding &apos;forbidden&apos; text into code to trigger safety refusals in AI-mediated security scanners, effectively bypassing automated analysis.</description><pubDate>Fri, 19 Jun 2026 09:50:19 GMT</pubDate><category>AI Bypass</category><category>Adversarial AI</category><category>Prompt Injection</category><category>Malware Obfuscation</category><category>Bioinformatics</category></item><item><title>Microsoft Copilot &apos;SearchLeak&apos; Attack: AI Prompt Injection Data Theft</title><link>https://runtimerebel.com/blog/microsoft-copilot-searchleak-attack-ai-prompt-injection-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-copilot-searchleak-attack-ai-prompt-injection-data-theft</guid><description>Analysis of the critical Microsoft Copilot &apos;SearchLeak&apos; attack. Learn how prompt injection allowed 1-click data theft and crucial defense strategies for AI applications.</description><pubDate>Tue, 16 Jun 2026 13:59:42 GMT</pubDate><category>Microsoft Copilot</category><category>AI Security</category><category>Prompt Injection</category><category>SearchLeak</category><category>Data Theft</category><category>LLM Security</category></item><item><title>OpenAI ChatGPT Lockdown Mode: Mitigating Prompt Injection Exfiltration</title><link>https://runtimerebel.com/blog/openai-chatgpt-lockdown-mode-mitigating-prompt-injection-exfiltration</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-chatgpt-lockdown-mode-mitigating-prompt-injection-exfiltration</guid><description>OpenAI introduces ChatGPT Lockdown Mode for personal accounts to prevent prompt injection attacks from exfiltrating sensitive data via external tools.</description><pubDate>Sat, 06 Jun 2026 16:29:48 GMT</pubDate><category>OpenAI</category><category>ChatGPT</category><category>Prompt Injection</category><category>Data Exfiltration</category><category>AI Security</category><category>Lockdown Mode</category></item><item><title>Google Gemini Hijack: Command Injection via Messaging Notifications</title><link>https://runtimerebel.com/blog/google-gemini-hijack-command-injection-via-messaging-notifications</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-gemini-hijack-command-injection-via-messaging-notifications</guid><description>Researchers demonstrate how Google Gemini voice assistant can be hijacked via malicious messaging notifications to control smart homes and start video calls.</description><pubDate>Thu, 04 Jun 2026 13:16:24 GMT</pubDate><category>Google Gemini</category><category>Prompt Injection</category><category>Voice Assistant</category><category>Iot Security</category><category>Android Security</category></item><item><title>Google Gemini Hijacked on Android via Poisoned Notifications</title><link>https://runtimerebel.com/blog/google-gemini-hijacked-on-android-via-poisoned-notifications</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-gemini-hijacked-on-android-via-poisoned-notifications</guid><description>Researchers demonstrate how WhatsApp and Slack notifications can trigger indirect prompt injection in Google Gemini, leading to memory poisoning.</description><pubDate>Wed, 03 Jun 2026 21:09:55 GMT</pubDate><category>Google Gemini</category><category>Android Security</category><category>Prompt Injection</category><category>AI Security</category></item><item><title>Google Gemini Indirect Prompt Injection via Malicious Notifications</title><link>https://runtimerebel.com/blog/google-gemini-indirect-prompt-injection-via-malicious-notifications</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-gemini-indirect-prompt-injection-via-malicious-notifications</guid><description>Security researchers demonstrate how malicious notifications can manipulate Google Gemini&apos;s voice assistant to perform unauthorized tasks or exfiltrate data.</description><pubDate>Wed, 03 Jun 2026 13:49:53 GMT</pubDate><category>Google Gemini</category><category>Prompt Injection</category><category>LLM Security</category><category>Hiddenlayer</category><category>Mobile Security</category></item><item><title>Evaluating AI Agent Security: 100 Agents Tested for Vulnerabilities</title><link>https://runtimerebel.com/blog/evaluating-ai-agent-security-100-agents-tested-for-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/evaluating-ai-agent-security-100-agents-tested-for-vulnerabilities</guid><description>An industry-first evaluation of 100 AI agents highlights critical security gaps in defense and the high impact of potential agentic compromises.</description><pubDate>Wed, 03 Jun 2026 13:49:24 GMT</pubDate><category>AI Security</category><category>LLM Vulnerabilities</category><category>Prompt Injection</category><category>Agentic AI</category></item><item><title>Meta AI Support Bot Exploited for Instagram Account Takeovers</title><link>https://runtimerebel.com/blog/meta-ai-support-bot-exploited-for-instagram-account-takeovers</link><guid isPermaLink="true">https://runtimerebel.com/blog/meta-ai-support-bot-exploited-for-instagram-account-takeovers</guid><description>Hackers manipulated Meta&apos;s AI support assistant to bypass authentication and seize high-profile Instagram accounts, including government entities.</description><pubDate>Mon, 01 Jun 2026 18:08:48 GMT</pubDate><category>Instagram</category><category>Meta AI</category><category>Account Takeover</category><category>Prompt Injection</category><category>Social Engineering</category></item><item><title>ChatGPT ChatGPhish Vulnerability: Web Summaries Lead to Phishing</title><link>https://runtimerebel.com/blog/chatgpt-chatgphish-vulnerability-web-summaries-lead-to-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/chatgpt-chatgphish-vulnerability-web-summaries-lead-to-phishing</guid><description>A newly disclosed ChatGPhish vulnerability allows attackers to leverage ChatGPT&apos;s Markdown trust for prompt injections and sophisticated phishing campaigns.</description><pubDate>Fri, 29 May 2026 20:53:47 GMT</pubDate><category>ChatGPT</category><category>ChatGPhish</category><category>OpenAI</category><category>Phishing</category><category>Prompt Injection</category><category>AI Security</category></item><item><title>Anthropic Claude Mythos-Class Models: Security Implications of Public Rollout</title><link>https://runtimerebel.com/blog/anthropic-claude-mythos-class-models-security-implications-of-public-rollout</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-claude-mythos-class-models-security-implications-of-public-rollout</guid><description>Anthropic confirms public rollout plans for Claude Mythos-class models, addressing previous delays caused by software security risks and safety concerns.</description><pubDate>Fri, 29 May 2026 01:00:17 GMT</pubDate><category>Anthropic</category><category>Claude Mythos</category><category>AI Security</category><category>Prompt Injection</category><category>Large Language Models</category></item><item><title>Microsoft RAMPART and Clarity: Securing AI Agents Against Exploitation</title><link>https://runtimerebel.com/blog/microsoft-rampart-and-clarity-securing-ai-agents-against-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-rampart-and-clarity-securing-ai-agents-against-exploitation</guid><description>Microsoft open-sources RAMPART and Clarity to provide developers with frameworks for red teaming and observing autonomous AI agents against prompt injection.</description><pubDate>Wed, 20 May 2026 17:10:34 GMT</pubDate><category>AI Security</category><category>Microsoft RAMPART</category><category>Prompt Injection</category><category>Red Teaming</category><category>AI Agents</category></item><item><title>Claude Code Sandbox Bypass: Anthropic Patches CLI Vulnerability</title><link>https://runtimerebel.com/blog/claude-code-sandbox-bypass-anthropic-patches-cli-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-code-sandbox-bypass-anthropic-patches-cli-vulnerability</guid><description>Anthropic recently addressed a sandbox bypass in Claude Code. This vulnerability could have allowed data exfiltration when combined with prompt injection.</description><pubDate>Wed, 20 May 2026 13:04:49 GMT</pubDate><category>Anthropic</category><category>Claude Code</category><category>Sandbox Bypass</category><category>AI Security</category><category>Prompt Injection</category></item><item><title>Secure AI Agent Integration: Preventing Production Data Loss</title><link>https://runtimerebel.com/blog/secure-ai-agent-integration-preventing-production-data-loss</link><guid isPermaLink="true">https://runtimerebel.com/blog/secure-ai-agent-integration-preventing-production-data-loss</guid><description>Organizations face catastrophic data loss as AI agents misinterpret prompts. Learn how to secure autonomous agents and implement strict guardrails.</description><pubDate>Fri, 01 May 2026 16:27:57 GMT</pubDate><category>Artificial Intelligence</category><category>Cloud Security</category><category>Data Protection</category><category>AI Agents</category><category>Prompt Injection</category></item><item><title>Malicious AI Prompt Injection Attacks: Google Red Team Insights</title><link>https://runtimerebel.com/blog/malicious-ai-prompt-injection-attacks-google-red-team-insights</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-ai-prompt-injection-attacks-google-red-team-insights</guid><description>Google reports a surge in AI prompt injection attacks, highlighting low-sophistication attempts and strategies for mitigating indirect prompt injection risks.</description><pubDate>Mon, 27 Apr 2026 12:49:10 GMT</pubDate><category>AI Security</category><category>Prompt Injection</category><category>LLM Vulnerabilities</category><category>Google Red Team</category></item><item><title>Security Risks of Agentic AI in Enterprise Ecosystems</title><link>https://runtimerebel.com/blog/security-risks-of-agentic-ai-in-enterprise-ecosystems</link><guid isPermaLink="true">https://runtimerebel.com/blog/security-risks-of-agentic-ai-in-enterprise-ecosystems</guid><description>Analysis of security risks in Agentic AI adoption, focusing on prompt injection, autonomous execution, and enterprise mitigation strategies.</description><pubDate>Wed, 22 Apr 2026 08:48:37 GMT</pubDate><category>Agentic AI</category><category>LLM Security</category><category>Prompt Injection</category><category>Enterprise Risk</category></item><item><title>Google Antigravity RCE via Prompt Injection — Mitigation Guide</title><link>https://runtimerebel.com/blog/google-antigravity-rce-via-prompt-injection-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-antigravity-rce-via-prompt-injection-mitigation-guide</guid><description>Google patched a critical RCE flaw in its AI-based Antigravity tool, stemming from a prompt injection vulnerability allowing sandbox escape and arbitrary code execution.</description><pubDate>Tue, 21 Apr 2026 16:32:40 GMT</pubDate><category>Google Antigravity</category><category>RCE</category><category>Prompt Injection</category><category>AI Security</category><category>Sandbox Escape</category></item><item><title>Cursor AI RCE via Indirect Prompt Injection — Mitigation Guide</title><link>https://runtimerebel.com/blog/cursor-ai-rce-via-indirect-prompt-injection-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cursor-ai-rce-via-indirect-prompt-injection-mitigation-guide</guid><description>Security researchers demonstrate how indirect prompt injection in Cursor AI could lead to full shell access on developer workstations. Patch immediately.</description><pubDate>Fri, 17 Apr 2026 08:43:51 GMT</pubDate><category>Cursor Ai</category><category>RCE</category><category>Prompt Injection</category><category>Developer Security</category><category>Johann Rehberger</category></item><item><title>Claude Code and Gemini CLI: Prompt Injection via Code Comments</title><link>https://runtimerebel.com/blog/claude-code-and-gemini-cli-prompt-injection-via-code-comments</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-code-and-gemini-cli-prompt-injection-via-code-comments</guid><description>Research reveals how Claude Code, Gemini CLI, and GitHub Copilot agents are vulnerable to prompt injection attacks via malicious source code comments.</description><pubDate>Thu, 16 Apr 2026 08:41:38 GMT</pubDate><category>Claude Code</category><category>Gemini CLI</category><category>GitHub Copilot</category><category>Prompt Injection</category><category>AI Security</category></item><item><title>Microsoft and Salesforce Patch Prompt Injection Flaws in AI Agents</title><link>https://runtimerebel.com/blog/microsoft-and-salesforce-patch-prompt-injection-flaws-in-ai-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-and-salesforce-patch-prompt-injection-flaws-in-ai-agents</guid><description>Researchers identified prompt injection vulnerabilities in Microsoft Copilot and Salesforce Agentforce that could allow attackers to exfiltrate sensitive data.</description><pubDate>Wed, 15 Apr 2026 12:32:01 GMT</pubDate><category>Microsoft Copilot</category><category>Salesforce Agentforce</category><category>Prompt Injection</category><category>Data Exfiltration</category><category>AI Security</category></item><item><title>Google Vertex AI Security: Mitigating AI Agent Weaponization</title><link>https://runtimerebel.com/blog/google-vertex-ai-security-mitigating-ai-agent-weaponization</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-vertex-ai-security-mitigating-ai-agent-weaponization</guid><description>Google patches security flaws in Vertex AI after Unit 42 researchers demonstrated how to weaponize AI agents for unauthorized data access and exfiltration.</description><pubDate>Wed, 01 Apr 2026 08:39:46 GMT</pubDate><category>Google Cloud</category><category>Vertex Ai</category><category>AI Agent Security</category><category>Prompt Injection</category><category>Unit 42</category></item><item><title>OpenAI Model Behavior Bug Bounty: Reporting AI Safety Risks</title><link>https://runtimerebel.com/blog/openai-model-behavior-bug-bounty-reporting-ai-safety-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-model-behavior-bug-bounty-reporting-ai-safety-risks</guid><description>OpenAI launches a bug bounty program targeting model abuse and safety risks. Learn how to report jailbreaks and bypasses to improve enterprise AI security.</description><pubDate>Fri, 27 Mar 2026 16:25:44 GMT</pubDate><category>OpenAI</category><category>Bug Bounty</category><category>LLM Security</category><category>AI Safety</category><category>Prompt Injection</category></item><item><title>Claude Chrome Extension Zero-Click Prompt Injection Vulnerability</title><link>https://runtimerebel.com/blog/claude-chrome-extension-zero-click-prompt-injection-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-chrome-extension-zero-click-prompt-injection-vulnerability</guid><description>A critical flaw in Anthropic&apos;s Claude Chrome extension allowed websites to silently inject malicious prompts using zero-click XSS techniques.</description><pubDate>Thu, 26 Mar 2026 16:31:26 GMT</pubDate><category>Anthropic</category><category>Claude</category><category>Prompt Injection</category><category>Browser Extension</category><category>XSS</category></item><item><title>Claudy Day: Prompt Injection and XSS Flaws Target Claude AI Users</title><link>https://runtimerebel.com/blog/claudy-day-prompt-injection-and-xss-flaws-target-claude-ai-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/claudy-day-prompt-injection-and-xss-flaws-target-claude-ai-users</guid><description>Researchers uncover &apos;Claudy Day&apos;, a trio of vulnerabilities in Anthropic&apos;s Claude AI that allow data theft through malicious Google search results.</description><pubDate>Wed, 18 Mar 2026 16:30:53 GMT</pubDate><category>Anthropic</category><category>Claude</category><category>Prompt Injection</category><category>Data Theft</category><category>LLM Security</category></item><item><title>Hiding Malicious Commands from AI via Font-Rendering Manipulation</title><link>https://runtimerebel.com/blog/hiding-malicious-commands-from-ai-via-font-rendering-manipulation</link><guid isPermaLink="true">https://runtimerebel.com/blog/hiding-malicious-commands-from-ai-via-font-rendering-manipulation</guid><description>Learn how attackers use font-rendering tricks to bypass AI safety filters and execute prompt injection attacks against LLM-powered assistants.</description><pubDate>Tue, 17 Mar 2026 16:30:27 GMT</pubDate><category>AI Security</category><category>Prompt Injection</category><category>Font Rendering</category><category>LLM Vulnerabilities</category><category>Adversarial AI</category></item><item><title>OpenClaw AI Agent Flaws: Prompt Injection and Data Exfiltration Risk</title><link>https://runtimerebel.com/blog/openclaw-ai-agent-flaws-prompt-injection-and-data-exfiltration-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/openclaw-ai-agent-flaws-prompt-injection-and-data-exfiltration-risk</guid><description>CNCERT warns of critical security flaws in OpenClaw AI agents, enabling prompt injection and data exfiltration due to weak default configurations.</description><pubDate>Sat, 14 Mar 2026 20:09:05 GMT</pubDate><category>OpenClaw</category><category>AI Security</category><category>Prompt Injection</category><category>CNCERT</category><category>Data Exfiltration</category></item></channel></rss>