Claude Desktop PromptFiction Vulnerability
Claude Desktop has a vulnerability called PromptFiction that can trick the AI agent into performing unintended actions, including data harvesting or code…
Claude Desktop has a vulnerability called PromptFiction that can trick the AI agent into performing unintended actions, including data harvesting or code…
GitHub Copilot CLI was successfully used in Manifold Security's proof of concept to demonstrate the Azure DevOps MCP server vulnerability, showing the…
Researchers from Tel Aviv University, Technion, and Intuit have identified a novel attack vector called HalluSquatting that exploits AI coding assistants' tendency…
Researchers at Noma Security have demonstrated a novel prompt injection attack, dubbed GitLost, that exploits GitHub Agentic Workflows to leak private repository…
Orca Security demonstrated RoguePilot, a prompt injection attack that uses hidden prompts in GitHub issues to make Copilot leak privileged tokens.
GitHub Agentic Workflows, a feature in public preview, allows AI agents to automate tasks but is vulnerable to indirect prompt injection attacks…
Anthropic Claude is one of the AI models that can power GitHub Agentic Workflows, which are vulnerable to the GitLost prompt injection…
Two critical vulnerabilities in Cursor, an AI-powered code editor, allow prompt injection attacks to escape the editor's safety sandbox and execute arbitrary…
CVE-2025-54135, known as CurXecute, is a vulnerability in Cursor discovered by Aim Security. A planted Slack message rewrites Cursor's ~/.cursor/mcp.json config and…
An indirect prompt-injection email processed by Anthropic's Claude Cowork through a Gmail connector can exfiltrate Slack tokens into an HTML draft.