Jan 08, 2026 •
Data Leak
|
#ZombieAgent
#Indirect Prompt Injection
#ChatGPT
The ZombieAgent attack, a bypass of the earlier ShadowLeak exploit, leverages an indirect prompt injection vulnerability in ChatGPT to achieve character-by-char...
Read Analysis →
Nov 06, 2025 •
Vulnerability
|
#Indirect Prompt Injection
#Large Language Models
#AI Supply Chain Security
Critical vulnerabilities in AI systems include structural flaws in AI-generated code and the ability to establish backdoors in large language models using minim...
Read Analysis →
Nov 05, 2025 •
Vulnerability
|
#Indirect Prompt Injection
#ChatGPT
#Data Exfiltration
Cybersecurity researchers have disclosed seven new vulnerabilities in OpenAI's GPT-4o and GPT-5 models, enabling indirect prompt injection attacks. These e...
Read Analysis →
Nov 04, 2025 •
Data Leak
|
#Indirect Prompt Injection
#Claude AI
#Data Exfiltration
A novel indirect prompt injection attack allows threat actors to compromise Anthropic's Claude AI Code Interpreter, leveraging its network features to exfi...
Read Analysis →
Oct 31, 2025 •
Vulnerability
|
#Indirect Prompt Injection
#Code Interpreter
#Data Exfiltration
A vulnerability in Anthropic's Claude AI allows attackers to leverage indirect prompt injection against its code interpreter feature. This exploit enables ...
Read Analysis →
Oct 09, 2025 •
Vulnerability
|
#Indirect Prompt Injection
#Remote Code Execution
#Agentic AI
Attackers can achieve remote code execution (RCE) on developer machines by leveraging indirect prompt injection against agentic AI developer tools. This is acco...
Read Analysis →
Oct 08, 2025 •
Vulnerability
|
#Indirect Prompt Injection
#Command Injection
#Remote Code Execution
An advanced attack chain exploits an LLM chatbot through indirect prompt injection (OWASP LLM01:2025) to achieve system prompt leakage and abuse excessive agenc...
Read Analysis →
Sep 25, 2025 •
Data Leak
|
#Indirect Prompt Injection
#Agentforce
#ForcedLeak
Researchers discovered "ForcedLeak," a critical indirect prompt injection vulnerability (CVSS 9.4) within Salesforce's Agentforce AI platform. Th...
Read Analysis →
Aug 20, 2025 •
Vulnerability
|
#Indirect Prompt Injection
#Perplexity Comet
#Cross-domain access
A critical indirect prompt injection vulnerability was discovered in Perplexity's Comet AI assistant, allowing malicious instructions hidden in webpage con...
Read Analysis →
May 23, 2025 •
Vulnerability
|
#Indirect Prompt Injection
#GitLab Duo
#Source Code Exfiltration
A critical indirect prompt injection vulnerability was discovered in GitLab Duo Chat, an AI-powered coding assistant, allowing attackers to embed hidden instruc...
Read Analysis →
May 13, 2025 •
Vulnerability
|
#Indirect Prompt Injection
#Multi-modal AI
#Data Exfiltration
This article details how indirect prompt injection exploits multi-modal AI agents by embedding malicious instructions within innocuous images or documents, lead...
Read Analysis →
May 13, 2025 •
Data Leak
|
#Indirect Prompt Injection
#Multi-modal AI Agents
#Data Exfiltration
Multi-modal AI agents are susceptible to indirect prompt injection, where hidden instructions in external sources like images or documents can trigger sensitive...
Read Analysis →