Tag

#prompt injection

77 stories taggedprompt injection · page 5 of 6.

Policy & Regulation

Estonia Wants to Give AI Agents Government-Issued IDs — With Spelled-Out Permission Scopes

The Baltic nation's AI Council is proposing state-backed digital identities for AI agents, defining exactly what they're allowed to do before they touch your data or your bank account.

2 min read
AI Security

SearchLeak: How a microsoft.com Link Could Have Drained a Copilot Tenant

Varonis Threat Labs chained three bugs in Microsoft 365 Copilot Enterprise Search into a one-click exfil path that lived behind a trusted Microsoft URL.

2 min read
AI Security

Agentjacking: Poisoned Sentry Error Reports Hijack AI Coding Assistants

Researchers describe a prompt-injection class that turns developer error-tracking pipelines into a remote code execution path against AI coding agents.

3 min read
AI Security

AI Web Agents Have No Reliable Prompt Injection Defenses, Benchmark Finds

Researchers ran 3,168 adversarial tests against GPT-5 and Gemini-powered agents. The 'Robust Behavior' outcome — agent completes task, attacker gets nothing — never appeared.

3 min read
AI Security

Researchers Turn OpenClaw Into a Confused Deputy With Hidden Prompts

Two teams show the self-hosted AI agent will execute attacker instructions smuggled inside contacts, location pins, and other benign-looking inputs.

3 min read
AI Security

Twelve Controls That Actually Matter Once AI Ships to Production

Visibility into AI applications is a starting point, not a security posture. Here is what ongoing monitoring and defense of production AI systems looks like in practice.

3 min read
AI Security

AI Red Teaming Grew Up. The Job Description Is Still Being Written.

The tools broke when LLMs arrived. Now the discipline is rebuilding itself in real time — and the threat model includes teenagers with too much free time.

3 min read
AI Security

OpenAI's Lockdown Mode Admits the Problem It Can't Quite Fix

The new containment feature reduces AI-enabled data exfiltration — it doesn't stop it. Experts are divided on whether enterprises should even trust a vendor to police itself.

3 min read
AI Security

OpenAI Ships ChatGPT 'Lockdown Mode' to Blunt Prompt-Injection Data Theft

The opt-in setting strips connectors and browsing tools that attackers have used to siphon data from logged-in sessions.

3 min read
AI Security

One GitHub Issue Was Enough to Pwn Repos Running Claude Code Action

A bug in Anthropic's Claude Code GitHub Action turned issue triage into arbitrary code execution — including, briefly, against the action's own repo.

2 min read
AI Security

A Single Notification Could Hijack Gemini on Android

Researchers showed how a poisoned WhatsApp, Slack or SMS alert could weaponize Google's voice assistant — no malicious app required.

2 min read
AI Security

Someone Finally Tested 100 AI Agents for Security. Here's the Framework They Used.

A new evaluation methodology ranks AI agents by vulnerability, blast radius, and defensive posture. The results are a useful corrective to vendor claims.

2 min read
AI Security

ChatGPhish: When ChatGPT's Markdown Renderer Becomes a Phishing Vector

Permiso researchers show how implicit trust in Markdown links and images inside ChatGPT responses turns the assistant into a credible delivery surface for prompt injection and credential theft.

3 min read
AI Security

You Can't Audit What You Can't See: The Agent Governance Hole Nobody Wants to Talk About

Enterprises are shipping AI agents into production without inventories, without trace pipelines, and without a coherent answer to a basic question: what is this thing actually doing?

3 min read
AI Security

Anthropic Wires Claude Into 28 Enterprise Security Platforms

The AI company is pushing deeper into corporate security stacks, connecting Claude to vendors including CrowdStrike, Okta, and Zscaler.

3 min read
© 2026 Threat Vectr