Gmail Image-Set() Bypass Enables Token Exfiltration via AI
Gmail's image-set() fallback can be abused to make external requests, enabling exfiltration of Slack tokens through prompt injection in AI-connected email workflows.
Gmail's image-set() fallback can be abused to make external requests, enabling exfiltration of Slack tokens through prompt injection in AI-connected email workflows.
Two security teams have demonstrated that OpenClaw, a popular self-hosted AI agent, can be tricked into executing attacker-controlled code or leaking sensitive…
A critical vulnerability in Microsoft 365 Copilot Enterprise Search, dubbed SearchLeak, could have allowed attackers to exfiltrate emails, files, and MFA codes…
EchoLeak is a prompt injection vulnerability in Microsoft 365 Copilot disclosed by Aim Security in June 2025. An attacker could craft an…
Microsoft researchers have disclosed a novel exploit chain named AutoJack that allows a single malicious web page to hijack an AI browsing…