CVE-2026-24299: Microsoft 365 Copilot Memory Modification via Indirect Prompt Injection
CVE-2026-24299 is associated with research by Johann Rehberger on memory writes and deletions through indirect prompt injection in Microsoft 365 Copilot, as…
CVE-2026-24299 is associated with research by Johann Rehberger on memory writes and deletions through indirect prompt injection in Microsoft 365 Copilot, as…
Researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads, dubbed "mind viruses," can spread between AI agents through editable system…
Mind viruses are self-propagating payloads that spread between AI agents via persistent prompt files like SOUL.md. Developed by Anthropic and EPFL researchers,…
The rapid adoption of AI agents in the enterprise has introduced a new security challenge: the Model Context Protocol (MCP) servers that…
Tracebit developed Context Bombs, using prompt injections as defensive canaries to trigger safety mechanisms and stop AI agents from malicious actions.
A zero-click remote code execution vulnerability in Cursor CLI uses indirect prompt injection to write a malicious executable to the workspace and…
A newly disclosed flaw in the way OpenAI, Anthropic, and Google handle hidden AI reasoning between API calls allowed researchers to recover…
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
New research presented at Black Hat USA 2026 reveals that CSS and HTML techniques can break out of email message boundaries to…
CSS pseudo-elements and opacity can hide instructions from humans while AI models like OpenAI's Atlas read them, leading to data exfiltration. Atlas…