Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > prompt injection
#prompt injection

AI Gateways Under Fire: Attackers Chain LiteLLM and MCP Flaws for Remote Code Execution

31 August 2026  |  dark6  |  Vulnerability

A 90-day honeypot study shows attackers systematically probing AI proxies, MCP servers, and agent frameworks like LangChain and Langflow, chaining authentication bypass and command-injection bugs into remote code...

>> read more

One Malicious Webpage Can Hijack Your AI Coding Agent Through an NVIDIA NemoClaw Flaw

27 August 2026  |  dark6  |  AI

A critical flaw in NVIDIA's NemoClaw tooling exposes a local AI inference server to the open network, letting a single malicious website hijack an AI agent via DNS...

>> read more

Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection

22 August 2026  |  dark6  |  AI

Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack...

>> read more

Researchers Find Matching RCE Flaws in Claude Code, Gemini CLI and Codex Coding Agents

9 August 2026  |  dark6  |  Vulnerability

Security researcher Elad Meged has uncovered a strikingly similar vulnerability pattern across AI coding agents from Anthropic, Google, and OpenAI, all traceable to how each vendor's surrounding 'harness'...

>> read more

Researchers Show How a Hidden Prompt Can Turn Word Copilot Into a Self-Spreading AI Worm

30 July 2026  |  dark6  |  AI

A newly disclosed weakness in Microsoft Copilot for Word shows how invisible text buried in a document can hijack the AI assistant, quietly alter content, and copy itself...

>> read more

GitLost: How a Single GitHub Issue Can Trick AI Agents Into Leaking Private Repos

8 July 2026  |  dark6  |  Vulnerability

Researchers at Noma Labs disclosed GitLost, a prompt-injection flaw that let a single crafted GitHub Issue trick AI-powered Agentic Workflows into leaking private repository contents publicly, using a...

>> read more

DuneSlide: Critical Zero-Click RCE Bugs in Cursor IDE Put Fortune 500 Developer Machines at Risk

2 July 2026  |  dark6  |  Vulnerability

Two critical zero-click RCE vulnerabilities (CVE-2026-50548, CVE-2026-50549) in Cursor IDE, dubbed DuneSlide, allow attackers to escape the AI coding agent sandbox via prompt injection with no user interaction...

>> read more

Microsoft Warns: Claude Code GitHub Action Exploitable via Prompt Injection to Leak CI/CD Secrets

8 June 2026  |  dark6  |  Vulnerability

Microsoft Threat Intelligence disclosed a prompt injection flaw in the Claude Code GitHub Action that allowed attackers to access /proc/self/environ and steal API keys from CI/CD runners. Anthropic...

>> read more