Affected Technology
Prompt Injection incidents
Prompt injection and indirect prompt attacks
Claude Security Vulnerability
Anthropic's Claude Opus 4.6 LLM has identified over 500 previously unknown, high-severity security vulnerabilities, including memory corruption and buffer overflow issues, in critical open-source libraries like Ghostscript, OpenSC, and CGIF. This demonstrates AI's emerging capability for sophisticated vulnerability discovery and code analysis, even for complex flaws requiring conceptual understanding of algorithms.
FlexPLM Remote Code Execution Vulnerability
A critical vulnerability, CVE-2025-12420 (CVSS 9.3), was patched in ServiceNow's AI platform, allowing unauthenticated user impersonation and unauthorized actions. Furthermore, researchers identified that default configurations in Now Assist AI Agents could facilitate "second-order prompt injection" attacks, enabling low-privileged users to exploit inter-agent communication for data access and privilege escalation.
Google Authentication Bypass
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis The Hacker News
Microsoft Copilot Remote Code Execution Vulnerability
Millions of AI agents imperiled by critical vulnerability in open source package Ars Technica
Kiro Prompt Injection Vulnerability
Evidence indicates that Kiro is affected by a security issue. Reported affected versions include 0.7.45.
AI Data Exposure
Fortinet Buys Virtue AI to Hunt Vulnerabilities in AI Agents Before Hackers Do Startup Fortune
AI Prompt Injection Vulnerability
Microsoft Copilot inadvertently revealed its secret input prompts, creating a critical information disclosure vulnerability. This prompt leakage allowed adversaries to exploit the AI model's underlying configuration, compromising its intended behavior.