Tag

#prompt injection

77 stories taggedprompt injection · page 4 of 6.

AI Security

Context Manipulation Attack 'BioShocking' Turns Agentic Browsers Into Credential Thieves

Researchers demonstrate how feeding poisoned context to AI-driven browser agents causes them to quietly drop safety guardrails and exfiltrate stored credentials.

2 min read
AI Security

Cursor IDE's Sandbox Cracked by Prompt Injection — No User Interaction Required

Two logic flaws in Cursor's command execution sandbox let attackers escape the isolation layer and run code on the underlying OS. Patches landed in April. The researchers say Cursor isn't alone.

2 min read
AI Security

DuneSlide: Two Cursor Bugs Turn a Prompt Into a Shell

A pair of 9.8-rated flaws in the AI code editor let a single crafted prompt escape the sandbox and execute arbitrary commands — no user approval required.

2 min read
AI Security

Poisoned Tool Descriptions Turn Helpful AI Agents Into Quiet Exfiltration Channels

Microsoft Incident Response demonstrates how a single malicious MCP-style tool description can coax an agent into leaking corporate data — without tripping a single policy check.

3 min read
AI Security

BioShocking: Prompt-Game Trick Pries Credentials From AI Browsers

Researchers at LayerX got six AI browsers and assistants — including ChatGPT Atlas, Perplexity's Comet, and Anthropic's Claude extension — to exfiltrate user logins by framing the attack as a game.

3 min read
AI Security

Poisoned Repos Can Trick Claude Code Into Opening a Reverse Shell

Researchers show that prompt injection hidden inside a repository's files is enough to turn Anthropic's agentic coding tool against the developer running it.

2 min read
AI Security

Prompt Injection in Git Repos Can Turn Claude Code Into a Reverse Shell Launcher

Malicious instructions buried in a repository's files can hijack Anthropic's Claude Code agent and open a backdoor on the developer's own machine — no obvious malware required.

2 min read
Threat Intelligence

North Korean Malware Tells AI Analyzers to Look Away

A macOS sample attributed to Pyongyang-linked actors contains prompts designed to make LLM-assisted security tools abandon their analysis. Defenders are starting to notice the pattern.

2 min read
AI Security

MCP's Enterprise Overhaul Hands Security Problems to Developers

A major revision to the Model Context Protocol repositions itself as enterprise-ready — then quietly offloads the hard security work onto the teams building on top of it.

3 min read
AI Security

Gaslight: A Rust macOS Stealer That Tries to Talk Your AI Analyst Out of Looking

The implant ships with an embedded prompt injection payload aimed at LLM-assisted reverse engineering tools — a small but telling escalation in adversarial UX.

3 min read
AI Security

AI Agents Are Being Manipulated Through the Data They Trust

Hidden content injections and context poisoning are turning autonomous AI pipelines into attack surfaces. Here's what defenders need to understand before deploying agents at scale.

2 min read
AI Security

Agentic AI Runs on Context. Feed It the Wrong Kind and Decisions Go Sideways Fast.

The core vulnerability in agentic AI systems isn't the model — it's the context window. Bad inputs, machine-speed outputs.

2 min read
Opinion

When the Trigger Pulls Itself: Agentic AI and the End of the Human-in-the-Loop

Every weapon in history extended a human decision. Agentic systems are the first that try to replace it — and the security implications are not theoretical.

2 min read
AI Security

Zero Trust as the AI Control Plane: What Zscaler's Vienna Pitch Means for APAC CISOs

AI agents are joining the workforce whether security teams are ready or not. At Zenith Live 2026, Zscaler made its case for why zero trust should govern them the same way it governs humans.

2 min read
AI Security

SearchLeak Shows How a Single Crafted URL Can Drain Your M365 Tenant

Varonis researchers chained three weaknesses in Copilot Enterprise Search into a full data-exfiltration path. Microsoft patched it. The attack class isn't going anywhere.

3 min read
© 2026 Threat Vectr