CuraSec

tag: Prompt-Injection · 25 items

2026-08-28 · GitHub Trending · source ↗ #ai-security#prompt-injection#tooling
  • Engineer — Learn: New read-only plugin worth evaluating if DeepSeek Harness is in your AI pipeline; covers prompt-injection detection and local config audit, but adoption is nascent (51 stars) with no enrichment signals to pressure a faster decision.
  • SOC/IR — Skip
  • Leader — Skip
  • Engineer — Plan: If your developers run Amazon Kiro IDE 0.7.45 on Windows, verify whether a patched version is available and update; the prompt injection → data exfiltration path via Kiro Powers is a real supply-chain risk for dev environments. No KEV or PoC signals elevate this to Act.
  • SOC/IR — Learn: No IOCs, active exploitation evidence, or ATT&CK-mappable detection surface are present; the item illustrates a prompt injection exfiltration pattern in agentic IDEs worth tracking as AI dev tooling becomes a threat surface.
  • Leader — Learn: Useful data point for AI tool governance: agentic IDEs can become data-exfiltration vectors via prompt injection, with no CVE or patch timeline disclosed yet — worth a line item when reviewing AI-assisted development tool policies.
2026-08-26 · The Hacker News · source ↗ #ai-security#prompt-injection#nvidia
  • Engineer — Plan: If you run Ollama locally or in AI agent pipelines alongside NemoClaw, this unauthenticated takeover path (likely DNS rebinding or CORS abuse against Ollama’s HTTP API) is a real exposure. Check Ollama’s network binding config now and watch for NVIDIA’s patch or mitigation advisory — no public PoC or KEV listing yet, but the attack surface is credible.
  • SOC/IR — Learn: No IOCs, no active exploitation, and no mapped TTPs — nothing to hunt or detect today. However, the technique (webpage-initiated control of a local AI agent instance to inject hidden instructions) is a novel attack class worth tracking as AI agent deployments grow in enterprise environments.
  • Leader — Learn: No breach or regulatory trigger here, but the finding illustrates that local AI agent tooling carries real attack surface — useful input for AI security policy and vendor risk reviews if your organization is adopting agentic AI infrastructure.
  • Engineer — Learn: Research demonstrates that prompt-level privacy policies fail to reliably prevent LLM agents from embedding protected attributes into generated tool-call arguments; if you ship agent pipelines, this motivates adding a purpose- and destination-aware inspection layer before tool execution, though no live exploit exists requiring an immediate change today.
  • SOC/IR — Learn: Novel disclosure vector where adversarial task context pressures agents into leaking protected fields via tool arguments — no IOCs, ATT&CK mappings, or active campaign to hunt for, but relevant background if your org monitors AI agent activity.
  • Leader — Learn: Controlled research showing prompt-level privacy guardrails in LLM agents are not a reliable enforcement boundary; useful context when developing AI governance policy for agent deployments, but no breach or regulation deadline requires immediate action.
2026-08-21 · The Hacker News · source ↗ #prompt-injection#ai-security#grok
  • Engineer — Learn: Novel indirect prompt injection variant that weaponizes web-page summarization to exfiltrate user metadata and conversation history from Grok; no patch or PoC signals, but informs how teams should sandbox AI agents that fetch and process external web content.
  • SOC/IR — Skip
  • Leader — Learn: If employees use Grok for work tasks, this technique demonstrates that malicious web pages can silently exfiltrate prompt content; worth referencing when reviewing AI-tool acceptable-use policies, but no active exploitation warrants immediate action.
2026-08-19 · The Hacker News · source ↗ #ai-agents#prompt-injection#research
  • Engineer — Learn: Novel attack class showing that writable system-prompt state files in multi-agent harnesses can carry self-propagating payloads between agents; no exploitation in the wild yet, but engineers building agentic pipelines should treat those files as untrusted input surfaces and avoid giving agents write access to other agents’ system prompts.
  • SOC/IR — Learn: Pure research with no IOCs, no ATT&CK mapping, and no detected campaigns; no hunt or detection to write today, but worth tracking as agentic AI deployments grow and this technique matures toward real-world use.
  • Leader — Plan: If the organization is deploying or evaluating multi-agent AI systems, this peer-reviewed research identifies a systemic risk class that warrants a policy guardrail — specifically around which components may write to agent state files — before agentic tooling scales further internally.
2026-08-18 · The Hacker News · source ↗ #mcp#ai-agents#prompt-injection
  • Engineer — Learn: No enrichment signals (no KEV, PoC, or active exploitation), but the attack surface is real: plaintext secrets in MCP config files and over-permissioned access are design-level risks engineers should factor in when deploying AI agent infrastructure. Audit any existing MCP deployments for credential storage and permission scope before expanding use.
  • SOC/IR — Learn: No IOCs, TTPs, or detection artifacts are surfaced here, but the ‘server running before security teams know’ framing highlights a shadow-AI discovery gap worth tracking. No immediate detection work is possible from this summary alone.
  • Leader — Plan: If the organization is adopting AI agents or MCP-based tooling, this is a quarter-horizon governance signal: establish an MCP server inventory policy and access-permission standard before the deployment footprint grows and secret exposure becomes a reportable incident.
2026-08-11 · The Hacker News · source ↗ #ai-security#mcp#prompt-injection
  • Engineer — Plan: AI coding assistants with MCP integrations are actively used in engineering workflows and this technique can bypass safety refusals to steal SSH keys, env secrets, and source code. Audit all connected MCP servers, restrict to explicitly trusted/internal ones, and review what credential stores and source directories your AI assistant can reach.
  • SOC/IR — Learn: Instruction-splitting to evade AI safety filters is a novel exfiltration technique worth understanding, but no IOCs, ATT&CK mappings, or detection surface are provided here — file this as an emerging technique to monitor as tooling matures.
  • Leader — Plan: Widespread enterprise adoption of AI coding assistants creates a new third-party risk vector: a malicious or compromised MCP server can silently exfiltrate source code and credentials. Establish an approved-MCP-server policy before your engineering teams expand AI tool integrations this quarter.
  • Engineer — Learn: Multi-step indirect prompt injection significantly raises attack success rates on computer-use agents (up to 72.9% for GPT-4o-mini at three-step depth), which is directly relevant to teams building or deploying agentic AI systems; no patch exists, but understanding this attack class should inform how you design sandboxing, permission scopes, and input validation for any CUA deployment.
  • SOC/IR — Learn: This research formalizes a new attack class against AI agents that may soon appear in enterprise environments; no active exploitation or IOCs reported, but understanding multi-step injection techniques will help detection engineers think ahead about behavioral anomalies in agentic workflows.
  • Leader — Learn: If your organization is piloting or deploying computer-use AI agents, this benchmark demonstrates meaningful safety gaps in current state-of-the-art systems; worth factoring into your AI governance policy and vendor evaluation criteria before broader rollout.
  • Engineer — Act: Two independent attack paths were found; only one is confirmed patched, leaving a live exfiltration surface in any Rovo-enabled Atlassian instance. Disable or restrict Rovo access to sensitive projects until Atlassian confirms both routes are fully remediated.
  • SOC/IR — Plan: The technique — hiding adversarial instructions in Rovo-readable content to trigger outbound data sends — is a concrete TTP worth building a detection for. Create a hunt query for anomalous outbound connections originating from Atlassian services to external hosts.
  • Leader — Act: If your organization uses Atlassian Rovo, one exfiltration route remains unpatched, meaning confidential Jira and Confluence data accessible to any signed-in user is at risk today. Confirm with your Atlassian admin whether Rovo is active, assess the data exposure scope, and request Atlassian’s remediation timeline before this surfaces in customer security questionnaires.
2026-08-07 · The Hacker News · source ↗ #prompt-injection#ci-cd#ai-coding-agents
  • Engineer — Act: If your team runs Claude Code or Gemini CLI in CI pipelines under vendor-default configuration, an unprivileged GitHub issue can reach your runner and exfiltrate CI secrets — audit all AI agent CI integrations now, restrict what secrets are scoped to those runners, and disable issue-triggered agent workflows until hardened configurations are documented.
  • SOC/IR — Plan: This Black Hat presentation defines a new TTP category — prompt injection via issue trackers targeting AI coding-agent CI workflows — worth building detections for; plan to monitor for anomalous CI runner invocations originating from issue events and unexpected secret-access patterns in pipeline logs.
  • Leader — Plan: Default configurations of AI coding agents from major vendors expose CI secrets to anyone who can open a GitHub issue — assess whether engineering teams have deployed these tools in CI/CD pipelines this quarter and establish an approval policy for AI agent access to production secrets before adoption widens.
  • Engineer — Learn: Novel attack class: hidden payloads in pre-filled AI deep links can alter LLM memory without user awareness. No exploitation signals or PoC, but engineers building AI-integrated features should audit any ‘Ask AI’ button implementations for unsanitized prompt passthrough.
  • SOC/IR — Learn: No IOCs, ATT&CK mapping, or active campaign indicators are present. Worth tracking as AI assistant adoption grows, but there is no detection surface or hunt query to act on today.
  • Leader — Plan: This attack class is relevant to any enterprise deploying AI assistants with memory or context features; factor it into AI acceptable-use policy and vendor evaluation criteria before broader rollout.
2026-08-04 · The Hacker News · source ↗ #prompt-injection#ai-agents#supply-chain
  • Engineer — Plan: Google already removed the affected workflows, but the pattern — a public GitHub issue prompt-injecting a triage agent into triggering a privileged code-fixing bot — applies to any AI pipeline where untrusted input can influence an agent holding elevated credentials. Audit your own ADK or similar agent workflows to ensure public-facing inputs cannot reach privileged action agents, and enforce least-privilege scoping on any bot collaborators.
  • SOC/IR — Learn: This demonstrates a novel escalation path: prompt injection via public GitHub issues → triage agent manipulation → privileged bot action. No IOCs or active exploitation are reported, but detection engineers building coverage for AI agent abuse should note this TTP as a new vector to model.
  • Leader — Plan: If your organization uses ADK or similar AI-powered developer tooling with privileged repository access, initiate a permission-scope review this quarter; the finding illustrates that AI agents integrated into development workflows can become unexpected privilege-escalation paths, which warrants a policy guardrail before broader adoption.
  • Engineer — Learn: Identifies a novel design flaw where LLM memory consolidation strips trust-level metadata from external inputs, letting injected content inherit user-level authority. No patch cycle applies yet, but teams building agentic systems with persistent memory should review their memory consolidation pipelines against this authority-amplification model.
  • SOC/IR — Learn: No IOCs, active exploitation, or detection surface currently exist; this is pre-deployment research. Worth tracking as AI agent adoption grows, as it describes an attack class that would be difficult to detect with existing SIEM/EDR tooling.
  • Leader — Learn: Establishes a concrete risk category for enterprise LLM agent deployments — memory subsystems can be poisoned to escalate trust silently. Useful framing for AI governance discussions, but no vendor exposure or regulatory deadline triggers action this quarter.
  • Engineer — Learn: The paper’s four-property model (Source Authorization, Task Alignment, Action Alignment, Data Isolation) offers a useful design lens for teams building agentic systems, but no running system requires a change today — absorb when designing agent authorization boundaries.
  • SOC/IR — Learn: Reframing indirect prompt injection as a Source Authorization violation is a useful mental model for thinking about what agent behaviors to monitor, but the paper yields no IOCs, detection rules, or hunt queries.
  • Leader — Skip
2026-07-22 · The Hacker News · source ↗ #prompt-injection#azure-devops#ai-agents
  • Engineer — Act: If you run Microsoft’s official Azure DevOps MCP server for AI code review, disable or restrict the PR-description tool until Microsoft ships a patched version with prompt-injection guardrails; an attacker with only PR-comment access can pivot the agent into unintended projects and exfiltrate output.
  • SOC/IR — Plan: No published IOCs, but build detection for anomalous AI agent cross-project access in Azure DevOps audit logs — unusual MCP tool invocations touching repos outside the agent’s expected scope are the behavioral signal to hunt for.
  • Leader — Plan: This illustrates a systemic gap in AI coding-agent deployments: prompt injection via developer workflow inputs can bypass access controls; use this as a prompt to add MCP/AI-agent integration scope to your existing AI governance policy review this quarter.
2026-07-22 · The Hacker News · source ↗ #prompt-injection#agentic-ai#ide-security
  • Engineer — Plan: Developers running Kiro should update to the patched version; also review agentic tool permissions and consider whether your workflows allow Kiro to fetch and process arbitrary external URLs without human review of rendered content.
  • SOC/IR — Learn: This demonstrates a concrete prompt-injection-to-RCE chain in an agentic coding IDE — no IOCs or active exploitation to hunt for now, but the attack class (hidden page text hijacking agent actions) is worth understanding as AI coding tools spread across developer estates.
  • Leader — Skip
2026-07-21 · The Hacker News · source ↗ #ai-agents#prompt-injection#android
  • Engineer — Learn: Researchers demonstrated a novel attack chain — invisible overlay text on Android feeds malicious instructions to an AI agent framework, which then executes commands on the host PC. No patch, KEV, or PoC is available yet, but this changes how secure AI agent pipelines should be architected (sandboxed execution context, input validation on screen-scraped content).
  • SOC/IR — Learn: No IOCs, active campaigns, or actionable detection surface are described; the value is understanding the emergent attack class of UI-layer prompt injection into agent frameworks, which may inform future alert logic as mobile AI agents reach enterprise environments.
  • Leader — Plan: This research confirms that AI agent deployments carry a concrete lateral-movement risk before defenses mature; if your org is evaluating or piloting mobile AI agents, prioritize an AI usage policy and architecture review for agent sandboxing this quarter before broader rollout.
  • Engineer — Learn: Research proposes interposing a deterministic symbolic controller with signed hash-chained instruction streams between LLM agents and privileged tools to prevent prompt-injection-driven authorization bypass — worth reviewing when architecting AI agent pipelines with privileged tool access, but no production implementation exists to adopt yet.
  • SOC/IR — Skip
  • Leader — Learn: Highlights a structural gap in current AI agent deployments: identity-based auth doesn’t constrain which actions an authenticated agent can take at runtime, creating hijack risk relevant to any enterprise adopting agentic workflows; useful framing for AI governance policy discussions.
  • Engineer — Plan: Teams deploying AI agents (coding assistants, browser agents) should audit what external data sources agents consume and add output-validation gates before agents take irreversible actions like purchasing, executing shell commands, or committing code.
  • SOC/IR — Learn: Useful for understanding a new class of agent-manipulation attacks that could be used as an initial-access vector in environments with autonomous AI tooling, but no IOCs or active exploitation reported to act on now.
  • Leader — Plan: As AI agents are deployed internally, establish a policy requiring human-in-the-loop approval for high-stakes agent actions (financial transactions, code execution) before agent autonomy is expanded this quarter.
2026-07-16 · The Hacker News · source ↗ #prompt-injection#ai-security#red-teaming
  • Engineer — Learn: OpenAI’s internal adversarial training methodology for prompt injection offers design patterns worth studying if you’re building or securing LLM-based applications, but no patch or configuration action is required today.
  • SOC/IR — Skip
  • Leader — Learn: Understanding that major AI providers are investing in automated red-teaming for prompt injection is useful context for evaluating AI vendor security posture and shaping internal AI usage policies.
  • Engineer — Learn: Novel prompt-injection variant that abuses persistent agent memory via a malicious email payload; no patch or KEV exists, but engineers building AI agents with memory + inbox access should audit whether memory writes can be triggered by untrusted input and add confirmation gates before persisting new user ‘facts’.
  • SOC/IR — Learn: No IOCs, ATT&CK mappings, or active exploitation reported; the attack’s stealthiness makes detection at the SIEM/EDR layer impractical without application-layer logging of memory writes, so this is awareness context for future detection design rather than an actionable hunt.
  • Leader — Plan: Organizations piloting AI assistants with memory and email access now have a concrete manipulation risk to include in AI deployment governance — draft or update your AI agent policy this quarter to require human approval before agents persist new user-context facts sourced from inbound messages.
  • Engineer — Plan: GitHub Copilot is broadly deployed on developer workstations; a public PoC exists for this RCE-via-prompt-injection path, but EPSS is 0.03 and it is not KEV-listed. Check for an available Copilot update and audit whether your pipelines or editors process untrusted file content through Copilot without sandboxing.
  • SOC/IR — Learn: Prompt injection as an RCE delivery mechanism in AI coding assistants is a novel developer-endpoint attack class worth adding to your threat model, but the summary provides no IOCs or ATT&CK-mappable TTPs to act on for detection tuning today.
  • Leader — Plan: If your organization deploys GitHub Copilot to developers (very common), a demonstrated RCE path represents a developer-workstation supply-chain risk; confirm with engineering whether a patched version is available and assess exposure this quarter before exploitation pressure rises.
  • Signals: CVE-2025-53773 — CISA KEV: not listed, EPSS 0.03, public PoC on GitHub
2026-07-11 · BleepingComputer · source ↗ #prompt-injection#ai-agents#supply-chain
  • Engineer — Plan: Research-grade but practical: any AI coding agent with access to .env or secrets files is a potential exfiltration path via a malicious image in a PR. Audit what filesystem scope your AI code-review agents hold, and restrict or deny access to credential files and secret stores.
  • SOC/IR — Learn: Novel TTP — prompt injection embedded in images bypasses AI reviewers that never inspect image content, then coerces coding agents into exfiltrating secrets. No active exploitation or IOCs reported; file for future detection work around anomalous AI-agent file reads.
  • Leader — Plan: Demonstrates that AI coding-agent tools carry unchecked secret-exfiltration risk through a non-obvious vector. Before broader AI agent adoption, establish a policy governing what repository paths and credentials these tools may access, and confirm existing vendor tools have equivalent controls.
2026-07-11 · CrowdStrike Blog · source ↗ #prompt-injection#ai-security#llm
  • Engineer — Learn: New prompt injection techniques are relevant to engineers building or integrating LLM-powered features; read to update threat model for AI application design, but no patch or config action is indicated without a summary or enrichment signals.
  • SOC/IR — Learn: Awareness of emerging prompt injection TTPs may eventually inform detections for AI-adjacent pipelines, but with no IOCs, ATT&CK mappings, or exploitation detail available, there is nothing actionable to hunt or tune today.
  • Leader — Skip