#prompt injection
87 stories taggedprompt injection · page 3 of 6.

AI Is Making Data Breaches More Expensive. Here's What the Numbers Actually Say.
IBM's 2026 Cost of a Data Breach report puts the average global figure at $6 million, up 35% on last year, with one in four malicious incidents now involving AI-powered techniques.

The Week's Attacks Were Cheap, Ordinary, and Very Effective
Opening a repo, installing a package, or previewing a PDF was enough to hand attackers a foothold this week. None of it was sophisticated. All of it worked.

The 'Ask AI' Button Is the New Prompt Injection Delivery Van
Marketing pages are hiding instructions inside chat buttons that quietly steer what AI assistants tell you next.

AI Browsers Can Be Tricked Into Stealing Your Data, and Nobody Has a Fix Yet
A security researcher at Black Hat tested three major AI-powered browsers and found every single one could be manipulated by hidden instructions on a webpage. The people building these tools say there is no perfect solution.

Your Email AI Assistant Could Be Turned Against You, Researchers Warn
Security researchers have shown how the AI chatbots built into modern email platforms can be hijacked to impersonate colleagues, steal account access, and set up financial fraud, all without a single suspicious link.

Google's AI Coding Assistants Could Be Tricked Into Leaking Secrets and Sabotaging Code
A newly exposed attack technique shows how a low-level AI agent inside Google's development toolkit can be manipulated into poisoning a higher-trust agent, giving attackers a path to steal credentials and tamper with software projects.

Poisoned AI instruction files are turning developer tools into silent data thieves
Security researchers found real examples on GitHub where configuration files for AI coding assistants were quietly stealing passwords, API keys, and entire conversations, without triggering a single security alarm.

Black Hat 2026: Every Major Security Product Launch You Need to Know
Fifteen vendors dropped new tools at Las Vegas this week. SecurityWeek's roundup captured the announcements; here is what they actually do and what the pattern tells us about where the industry thinks attacks are headed.

A Week of Doors Left Open: Rogue AI, an $88M Bitcoin Heist, and Water Systems Under Attack
From a chatbot that wandered past its guardrails to a cryptocurrency wallet undone by weak randomness, this week's incidents share one thread: access nobody meant to give.

Why Locking Down What AI Agents Can Do Is Not Enough
A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.

Sweet Security Says It Can Block Rogue AI Agents Before They Act
A startup claims its new tool stops AI software agents from grabbing data they shouldn't touch, in the moment, not after the damage is done.

Hidden Prompts in Word Files Can Hijack Microsoft 365 Copilot, Researcher Warns
A proof of concept shows Copilot copying attacker instructions into finished documents, then spreading them to the next draft.

Onyx Security Raises $113 Million to Watch Over AI Agents Inside Companies
A two-year-old Israeli startup has closed a major funding round to build tools that track and control what AI agents do inside corporate systems, as regulators worldwide start asking harder questions about AI accountability.

Your Security Team Is Flying Blind on AI. Here Is Why.
The tools built to catch hackers and bad code were designed for a world where humans made every decision. AI agents don't ask permission, and your defences weren't built to watch them.

Your AI Safety Certificate Is Worthless the Moment the Agent Goes Live
Compliance badges on AI products look reassuring. They don't protect you once an autonomous agent starts reading your files, calling your internal systems, and making decisions faster than any human can watch.