Tag

#prompt injection

87 stories taggedprompt injection · page 5 of 6.

Close-up, edge-to-edge 16:9 photograph of a glowing circuit board with streams of faintly visible text and code cascading across its surface in soft blue and wh
AI Security

CrowdStrike Flags Five New Ways Criminals Can Trick AI Into Obeying Them

Researchers have mapped out a fresh set of prompt injection attacks, where criminals feed deceptive instructions to AI systems to make them behave in harmful ways. Here is what each one does and why ordinary employees are part of the risk picture.

3 min read
Full-frame overhead shot of a developer's dark wooden desk, a laptop screen glowing with abstract lines of code, a small red warning icon reflected on the keybo
AI Security

AI Coding Assistants Can Be Tricked Into Running the Very Malware They Were Asked to Find

A proof-of-concept from the AI Now Institute shows Claude Code and OpenAI's Codex executing attacker-supplied code when asked to review it in autonomous mode.

3 min read
A close-up, sharply focused photograph of a glowing laptop screen in a darkened office, showing lines of green and white code reflecting faintly on a glass desk
AI Security

A Hidden Note in a Bug Report Tricked GitHub's AI Into Leaking Company Secrets

Researchers showed how a single crafted message in a public GitHub issue could fool an AI assistant into reading private code and posting it online for anyone to see.

3 min read
Photoreal news-editorial 16:9 image
AI Security

Researchers Show How a Fake GitHub Comment Can Trick AI Tools Into Leaking Secret Code

A crafted public comment on GitHub can manipulate AI-powered automation into handing over data from private repositories, no password required.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
AI Security

A Hidden Command in a GitHub Issue Can Silently Steal a Company's Private Code

Researchers found a flaw in GitHub's AI automation tool that lets an outsider read an organisation's private repositories by hiding plain-English instructions inside a public bug report.

3 min read
Photoreal news-editorial 16:9 photograph of a close-up view of a glowing computer screen displaying abstract flowing green and amber data streams, with a physic
AI Security

AI Agents Can Be Tricked Into Sending Money. Zscaler Has the Data.

A new study shows that some expensive, enterprise-grade AI assistants fall for hidden instructions that most humans would ignore, and the real danger is far bigger than a fake three-dollar fee.

3 min read
A photoreal overhead view of a domestic living room shelf holding a small black streaming box, a home router with blinking lights, and a smartphone, all connect
Threat Intelligence

The Weak Link This Week Wasn't Code. It Was Trust.

From home streaming boxes turned into criminal relays to AI assistants tricked by hidden instructions, this week's incidents share one root cause: systems trusting the wrong thing.

4 min read
Close-up top-down view of a glowing digital web of interconnected nodes on a dark surface, with one node subtly emitting a hidden pulse of light in a different
AI Security

Hackers Are Hiding Instructions Inside Websites to Make AI Assistants Send Crypto Payments

Two newly discovered attack campaigns show how criminals can secretly hijack AI browsing agents by planting hidden commands in ordinary-looking web pages.

3 min read
A close-up top-down view of a mechanical keyboard on a dark desk, its keys softly lit by the cool blue glow of a monitor displaying abstract cascading lines of
Vulnerabilities

Popular AI Coding Tool Cursor Has Flaws That Could Let Attackers Run Code on Your Computer

Security researchers found two vulnerabilities in the Cursor AI code editor that could allow an attacker to silently take control of a developer's machine, no click required.

3 min read
Macro photograph of a glowing computer terminal screen in a dark room displaying cascading green lines of code and error log text, with a single line subtly hig
AI Security

A Fake Error Message Hijacked AI Coding Assistants — and Security Tools Saw Nothing

Researchers planted a single bogus bug report in a popular developer service and watched AI coding agents obediently run the attackers' code. No password stolen. No alarm raised.

3 min read
AI Security

Context Manipulation Attack 'BioShocking' Turns Agentic Browsers Into Credential Thieves

Researchers show how poisoned context fed to AI-driven browser agents causes them to drop safety guardrails and quietly exfiltrate stored credentials.

3 min read
AI Security

Cursor IDE's Sandbox Cracked by Prompt Injection — No User Interaction Required

Two logic flaws in Cursor's command execution sandbox let attackers escape the isolation layer and run code on the underlying OS. Patches landed in April. The researchers say Cursor isn't alone.

3 min read
AI Security

DuneSlide: Two Cursor Bugs Turn a Prompt Into a Shell

A pair of 9.8-rated flaws in the AI code editor let a single crafted prompt escape the sandbox and execute arbitrary commands, no user approval required.

3 min read
AI Security

Poisoned Tool Descriptions Turn Helpful AI Agents Into Quiet Exfiltration Channels

Microsoft Incident Response shows how a single malicious MCP tool description can coax an agent into leaking corporate data without tripping a single policy check.

3 min read
AI Security

BioShocking: Prompt-Game Trick Pries Credentials From AI Browsers

Researchers at LayerX got six AI browsers and assistants, including ChatGPT Atlas, Perplexity's Comet and Anthropic's Claude extension, to exfiltrate user logins by framing the attack as a game.

3 min read
© 2026 Threat Vectr