Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > prompt injection
#prompt injection

GitLost: How a Single GitHub Issue Can Trick AI Agents Into Leaking Private Repos

8 July 2026  |  dark6  |  Vulnerability

Researchers at Noma Labs disclosed GitLost, a prompt-injection flaw that let a single crafted GitHub Issue trick AI-powered Agentic Workflows into leaking private repository contents publicly, using a...

>> read more

DuneSlide: Critical Zero-Click RCE Bugs in Cursor IDE Put Fortune 500 Developer Machines at Risk

2 July 2026  |  dark6  |  Vulnerability

Two critical zero-click RCE vulnerabilities (CVE-2026-50548, CVE-2026-50549) in Cursor IDE, dubbed DuneSlide, allow attackers to escape the AI coding agent sandbox via prompt injection with no user interaction...

>> read more

Microsoft Warns: Claude Code GitHub Action Exploitable via Prompt Injection to Leak CI/CD Secrets

8 June 2026  |  dark6  |  Vulnerability

Microsoft Threat Intelligence disclosed a prompt injection flaw in the Claude Code GitHub Action that allowed attackers to access /proc/self/environ and steal API keys from CI/CD runners. Anthropic...

>> read more

OpenAI Launches ChatGPT Lockdown Mode to Block Prompt Injection Data Exfiltration

8 June 2026  |  dark6  |  AI

OpenAI has released ChatGPT Lockdown Mode, a new security feature that disables outbound network capabilities to cut off data exfiltration pathways exploited in prompt injection attacks. Available to...

>> read more

Google Gemini Voice Assistant Hijacked via WhatsApp, Slack and SMS: Researchers Bypass All Google Defenses

5 June 2026  |  dark6  |  Vulnerability

SafeBreach researchers demonstrate how attackers can silently hijack Google Gemini through malicious payloads in WhatsApp, Slack, SMS, and other messaging app notifications, bypassing all of Google patched defenses...

>> read more

AI Supply Chain Attack: 575+ Malicious Skills on Hugging Face and ClawHub Deliver Trojans, Cryptominers, and AMOS Stealer

9 May 2026  |  dark6  |  AI

Threat actors have uploaded 575+ malicious AI skills to ClawHub's OpenClaw ecosystem and abused Hugging Face repositories to deliver trojans, cryptominers, and AMOS Stealer. The campaign uses indirect...

>> read more