#prompt injection
77 stories taggedprompt injection.

How a Rogue Helper Tool Can Trick an AI Coding Assistant Into Leaking Your Secrets
Researchers show that a hostile plugin can smuggle out SSH keys and source code by breaking one big theft into small, innocent-looking steps.

GhostJacking: How Hackers Can Turn an AI Assistant Against Its Own Company
Researchers showed that a single blocked web request, already sitting in a firewall log, was enough to trick an AI agent into handing over a company's entire domain. Here is what that means for organisations using AI tools to manage their systems.

A Single Click Could Have Handed Hackers Your Company's Confluence and Jira Files
Researchers found a flaw in Atlassian's Rovo AI assistant that let an attacker steal data from widely used workplace tools with almost no effort from the victim.

Rovo, Atlassian's AI Assistant, Can Be Tricked Into Leaking Jira and Confluence Data
Two research teams showed how hidden instructions can turn Atlassian's built-in AI helper into a quiet data pipe. Only one of the tricks has been fully closed.

AI Is Making Data Breaches More Expensive. Here's What the Numbers Actually Say.
A new IBM report puts the average global cost of a data breach at $6 million for 2026, up 35% in a year, and for the first time, AI-powered attacks account for one in four of those incidents.

The Week's Attacks Were Cheap, Ordinary, and Very Effective
Opening a repo, installing a package, or previewing a PDF was enough to hand attackers a foothold this week. None of it was sophisticated. All of it worked.

The 'Ask AI' Button Is the New Prompt Injection Delivery Van
Marketing pages are hiding instructions inside chat buttons that quietly steer what AI assistants tell you next.

AI Browsers Can Be Hijacked by Hidden Instructions in Emails and Web Pages, Researchers Warn
A new attack class called 'PleaseFix' lets criminals slip fake commands into ordinary content, and the AI does the rest, using your own accounts against you.

AI Browsers Can Be Tricked Into Stealing Your Data, and Nobody Has a Fix Yet
A security researcher at Black Hat tested three major AI-powered browsers and found every single one could be manipulated by hidden instructions on a webpage. The people building these tools say there is no perfect solution.

Your Email AI Assistant Could Be Turned Against You, Researchers Warn
Security researchers have shown how the AI chatbots built into modern email platforms can be hijacked to impersonate colleagues, steal account access, and set up financial fraud, all without sending a single suspicious link.

Google's AI Coding Assistants Could Be Tricked Into Leaking Secrets and Sabotaging Code
A newly exposed attack technique shows how a low-level AI agent inside Google's development toolkit can be manipulated into poisoning a higher-trust agent, giving attackers a path to steal credentials and tamper with software projects.

Poisoned AI instruction files are turning developer tools into silent data thieves
Security researchers found real examples on GitHub where configuration files for AI coding assistants were quietly stealing passwords, API keys, and entire conversations, without triggering a single security alarm.

Black Hat 2026: Every Major Security Product Launch You Need to Know
Fifteen vendors dropped new tools at Las Vegas this week. Here is what they actually do, why it matters, and what the pattern of announcements tells us about where the industry thinks the next wave of attacks is coming from.

A Week of Doors Left Open: Rogue AI, an $88M Bitcoin Heist, and Water Systems Under Attack
From a chatbot that wandered past its guardrails to a cryptocurrency wallet undone by weak randomness, this week's incidents share one thread: access nobody meant to give.

Why Locking Down What AI Agents Can Do Is Not Enough
A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.