
ASCII smuggling jumps from AI prompt attacks to mass spam campaigns
Microsoft Defender for Office logged 2.5 million invisible-Unicode signatures within four days of a February spike.
Tag · 14 stories
Every story tagged Prompt Injection on AI Chat Daily.

Microsoft Defender for Office logged 2.5 million invisible-Unicode signatures within four days of a February spike.

Adversa researchers bypassed xAI's guardrails with AES-256-GCM ciphertext; xAI was told in June and the flaw still works.

Varonis got Copilot to disclose an undocumented ?autorun=1 flag that skipped user consent and exfiltrated inbox data on a single click.

A pro se litigant hid white-on-white AI instructions in pleadings to sway the court; the judge banned him from e-filing.

Around 20 flaws across AI browsers from OpenAI, Google, Anthropic, Microsoft, and Perplexity let researchers weaponize agentic browsing.

A paper at ICML shows OpenAI, Anthropic, Alibaba and DeepSeek models identify roles by style, not tags — making jailbreaks structurally hard to close.

The internal red-team model cut successful attack rates from over 90% on GPT-5 to under 23% on the new GPT-5.6.

Planting refusal-triggering strings in AWS decoy secrets cut agentic attacker admin takeover from 57% to 5% across five leading models.

Researchers show LLMs hallucinate repository names up to 100% of the time — and attackers can register those names in advance.

Varonis's SearchLeak exploit chain weaponized a crafted URL to make M365 Copilot exfiltrate emails, SharePoint docs, and OneDrive files.

The new setting disables live browsing, image retrieval, deep research, and agent mode for accounts handling sensitive data.

Attackers told Meta's AI customer support agent to change the email on target Instagram accounts — including the dormant Obama White House handle — and it complied.

Johannes Link hid an instruction in version 1.10.0 telling AI agents to delete jqwik tests and code, masked from human terminal view by ANSI escapes.
A maliciously crafted project description caused the company's AI build agent to leak environment variables to an external URL.
The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.
The briefing read inside teams at