#prompt injection
87 stories taggedprompt injection · page 4 of 6.

When AI Speaks Your Language But Its Security Doesn't
AI safety filters were built mostly in English. For companies operating across Europe's dozens of languages, that gap is already being used against them.

The Week Malware Wore a Friendly Face: Fake Extensions, Poisoned Packages and an Image That Talked to an AI
The payload wasn't the story this week. The disguise was.

A Hidden Comment in Azure DevOps Can Trick an AI Reviewer Into Stealing Code
Microsoft's official Azure DevOps MCP server passes pull request descriptions to AI agents without checking for hidden instructions, letting an outsider steer a reviewer's assistant into private projects.

A Poisoned Web Page Was Enough to Hijack Amazon's AI Coding Assistant
Researchers showed that Kiro, Amazon's AI-powered coding tool, could be tricked into running attacker code just by reading a booby-trapped web page.

Invisible Text on an Android Screen Can Hijack AI Phone Assistants, and Then the PC Behind Them
Researchers show how a rogue Android app can whisper hidden orders to open-source AI agents, then pivot the attack onto the computer running the show.

Fake Files That Stop Hackers: How 'Context Bombs' Crash AI Attack Agents
A security firm has found a way to halt automated AI attacks by planting decoy text that triggers the safety rules built into AI systems. In tests, AI-driven attack success rates dropped by up to 90%.

AI coding assistants get tricked into hacking their own developers
Researchers show that Cursor, OpenAI's Codex, Google's Gemini CLI and Antigravity can be nudged to write files that trusted tools outside the safety box then happily run.

A Week When Small Inputs Caused Big Damage
WordPress code execution, SonicWall zero-days, attacks on AI services, and a fresh SharePoint flaw made for a punishing seven days.

How a String of Morse Code Tricked an AI Into Wiring Real Money
A crypto heist nobody heard much about previews a dangerous new kind of attack that needs no stolen passwords, no malware, and no hacked firewall.

A single fake review can trick an AI agent into buying the wrong product
Researchers describe a new class of attack where planted content on trusted pages steers AI assistants into harmful actions without ever hijacking the task itself.

One Click Was All It Took to Hijack Anthropic's Claude AI
A flaw in the Claude Desktop app let attackers silently feed malicious instructions to the AI and steal private files. The bug is fixed, but the attack method points to a new category of risk.

The AI Blind Spot in Corporate Security: Why Old Traffic Inspection Is Falling Behind
Employees are pasting company secrets into ChatGPT and installing rogue browser add-ons. The security tools most firms rely on can't see any of it.

One Poisoned Email Can Rewrite What Your AI Assistant 'Remembers' About You
Researchers show how a single message can plant a false memory in an AI agent's long-term store, quietly steering its answers in every future chat.

The Week Trusted Software Turned Hostile: ShareFile, Citrix Bleed 2, and AI Coding Attacks
Automated bug-hunting is cutting both ways, and old flaws are still landing hits because patches sat in a queue.

'Ghostcommit' smuggles hacker instructions inside images to trick AI coding assistants
Researchers hid secret commands in an ordinary PNG file, walked past two popular AI code reviewers, and got a coding assistant to leak a project's passwords.