Claude got network access.
When enabled, it can also communicate with Anthropic APIs!
Twist: Attacker sets their own API key in prompt injection payload to upload user's data to their account 🔥
embracethered.com/blog/posts/2...
Claude got network access.
When enabled, it can also communicate with Anthropic APIs!
Twist: Attacker sets their own API key in prompt injection payload to upload user's data to their account 🔥
embracethered.com/blog/posts/2...
To rephrase the old joke: the S in VIBE coding stands for Security.
To rephrase the old joke: the S in VIBE coding stands for Security.
Arbitrary Code Execution via Indirect Prompt Injection
embracethered.com/blog/posts/2...
Arbitrary Code Execution via Indirect Prompt Injection
embracethered.com/blog/posts/2...
How Prompt Injection Exposes Manus' VS Code Server to the Internet
embracethered.com/blog/posts/2...
How Prompt Injection Exposes Manus' VS Code Server to the Internet
embracethered.com/blog/posts/2...
Sneaking Invisible Instructions by Developers in Windsurf
embracethered.com/blog/posts/2...
Sneaking Invisible Instructions by Developers in Windsurf
embracethered.com/blog/posts/2...
Windsurf: Memory-Persistent Data Exfiltration (SpAIware Exploit)
embracethered.com/blog/posts/2...
Windsurf: Memory-Persistent Data Exfiltration (SpAIware Exploit)
embracethered.com/blog/posts/2...
How Prompt Injection Leaks Developer Secrets
embracethered.com/blog/posts/2...
How Prompt Injection Leaks Developer Secrets
embracethered.com/blog/posts/2...
Remote Code Execution with Prompt Injection
embracethered.com/blog/posts/2...
Remote Code Execution with Prompt Injection
embracethered.com/blog/posts/2...
Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection
embracethered.com/blog/posts/2...
Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection
embracethered.com/blog/posts/2...
Data Exfiltration via Image Rendering Fixed in Amp Code
embracethered.com/blog/posts/2...
Data Exfiltration via Image Rendering Fixed in Amp Code
embracethered.com/blog/posts/2...
Invisible Prompt Injection Fixed by Sourcegraph
embracethered.com/blog/posts/2...
Invisible Prompt Injection Fixed by Sourcegraph
embracethered.com/blog/posts/2...
Google Jules is Vulnerable To Invisible Prompt Injection
embracethered.com/blog/posts/2...
Google Jules is Vulnerable To Invisible Prompt Injection
embracethered.com/blog/posts/2...
Jules Zombie Agent: From Prompt Injection to Remote Control
embracethered.com/blog/posts/2...
Jules Zombie Agent: From Prompt Injection to Remote Control
embracethered.com/blog/posts/2...
Vulnerable to Multiple Data Exfiltration Issues with prompt injection
embracethered.com/blog/posts/2...
Vulnerable to Multiple Data Exfiltration Issues with prompt injection
embracethered.com/blog/posts/2...
In short, all AI tools are vulnerable if one attaches external files and links to their prompts, leading to secrets leaks and remote code execution.
Johann publishes daily until the end of the month.
In short, all AI tools are vulnerable if one attaches external files and links to their prompts, leading to secrets leaks and remote code execution.
Johann publishes daily until the end of the month.
👉 Prompt injection exploit writes to Copilot config file & puts it into YOLO mode, and we get immediate RCE
🔥 Bypasses all user approvals
🛡️ Patch is out today. Update before someone else does it for you
embracethered.com/blog/posts/2...
👉 Prompt injection exploit writes to Copilot config file & puts it into YOLO mode, and we get immediate RCE
🔥 Bypasses all user approvals
🛡️ Patch is out today. Update before someone else does it for you
embracethered.com/blog/posts/2...
ZombAI Exploit with OpenHands: Prompt Injection To Remote Code Execution
embracethered.com/blog/posts/2...
ZombAI Exploit with OpenHands: Prompt Injection To Remote Code Execution
embracethered.com/blog/posts/2...
OpenHands and the Lethal Trifecta: How Prompt Injection Can Leak Access Tokens
embracethered.com/blog/posts/2...
OpenHands and the Lethal Trifecta: How Prompt Injection Can Leak Access Tokens
embracethered.com/blog/posts/2...
AI Kill Chain in Action: Devin AI Exposes Ports to the Internet with Prompt Injection
embracethered.com/blog/posts/2...
AI Kill Chain in Action: Devin AI Exposes Ports to the Internet with Prompt Injection
embracethered.com/blog/posts/2...
Spent $500 To Test Devin AI For Prompt Injection So That You Don't Have To
embracethered.com/blog/posts/2...
Spent $500 To Test Devin AI For Prompt Injection So That You Don't Have To
embracethered.com/blog/posts/2...
Amp Code: Arbitrary Command Execution via Prompt Injection Fixed
New novel TTP!
embracethered.com/blog/posts/2...
Amp Code: Arbitrary Command Execution via Prompt Injection Fixed
New novel TTP!
embracethered.com/blog/posts/2...