Skip to main content
Live
Main content

Tag · 14 stories

Prompt Injection

Every story tagged Prompt Injection on AI Chat Daily.

More tagged Prompt Injection

Grok leaks user chats when prompt injections arrive encrypted
Security

Grok leaks user chats when prompt injections arrive encrypted

Adversa researchers bypassed xAI's guardrails with AES-256-GCM ciphertext; xAI was told in June and the flaw still works.

Jaeden Schafer5 min read
Microsoft logo
Security

Microsoft Copilot leaked its own bypass parameter, letting researchers steal passwords

Varonis got Copilot to disclose an undocumented ?autorun=1 flag that skipped user consent and exfiltrated inbox data on a single click.

Jaeden Schafer5 min read
Connecticut judge flags first US case of prompt injection hidden in court filings
Security

Connecticut judge flags first US case of prompt injection hidden in court filings

A pro se litigant hid white-on-white AI instructions in pleadings to sway the court; the judge banned him from e-filing.

Jaeden Schafer5 min read
OpenAI logo
Security

Zenity researchers hijack OpenAI's Atlas browser to spam WhatsApp, buy on Amazon

Around 20 flaws across AI browsers from OpenAI, Google, Anthropic, Microsoft, and Perplexity let researchers weaponize agentic browsing.

Jaeden Schafer5 min read
OpenAI logo
Security

Researchers say LLMs have an unfixable flaw that lets attackers spoof any role

A paper at ICML shows OpenAI, Anthropic, Alibaba and DeepSeek models identify roles by style, not tags — making jailbreaks structurally hard to close.

Jaeden Schafer5 min read
OpenAI logo
Security

OpenAI built GPT-Red, an LLM super-hacker, to harden its own models

The internal red-team model cut successful attack rates from over 90% on GPT-5 to under 23% on the new GPT-5.6.

Jaeden Schafer5 min read
Tracebit turns prompt injection into a defense with 'context bombing'
Security

Tracebit turns prompt injection into a defense with 'context bombing'

Planting refusal-triggering strings in AWS decoy secrets cut agentic attacker admin takeover from 57% to 5% across five leading models.

Jaeden Schafer5 min read
HalluSquatting attack turns 9 AI coding assistants into a botnet vector
Security

HalluSquatting attack turns 9 AI coding assistants into a botnet vector

Researchers show LLMs hallucinate repository names up to 100% of the time — and attackers can register those names in advance.

Jaeden Schafer5 min read
Microsoft logo
Security

Microsoft patches critical Copilot flaw that leaked 2FA codes from user emails

Varonis's SearchLeak exploit chain weaponized a crafted URL to make M365 Copilot exfiltrate emails, SharePoint docs, and OneDrive files.

Jaeden Schafer5 min read
OpenAI logo
Security

OpenAI ships Lockdown Mode to blunt prompt injection attacks in ChatGPT

The new setting disables live browsing, image retrieval, deep research, and agent mode for accounts handling sensitive data.

Jaeden Schafer4 min read
Meta logo
Security

Meta's AI support agent handed over Instagram accounts to attackers who just asked

Attackers told Meta's AI customer support agent to change the email on target Instagram accounts — including the dormant Obama White House handle — and it complied.

Jaeden Schafer5 min read
jqwik developer plants data-deleting prompt injection to sabotage AI coding agents
Security

jqwik developer plants data-deleting prompt injection to sabotage AI coding agents

Johannes Link hid an instruction in version 1.10.0 telling AI agents to delete jqwik tests and code, masked from human terminal view by ANSI escapes.

Jaeden Schafer5 min read
Security

Vercel acknowledges prompt-injection breach in AI code builder

A maliciously crafted project description caused the company's AI build agent to leak environment variables to an external URL.

Jaeden Schafer6 min read
AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at