Damn it AI, stop lying to me and do what I say
A new report titled 'Proof, Not Trust' warns that AI agents connected to enterprise systems can be manipulated by adversarial text, citing incidents from 2012 to 2026 including a $440M Knight Capital …
A new report titled 'Proof, Not Trust' warns that AI agents connected to enterprise systems can be manipulated by adversarial text, citing incidents from 2012 to 2026 including a $440M Knight Capital …
A senior incident responder outlines a practical hour-by-hour playbook for the first 24 hours of an AI agent security incident, citing Anthropic's GTG-1002 campaign, Microsoft 365 Copilot's EchoLeak f…
Mcploitable, a new open-source project by agileAlligator, provides seven deliberately vulnerable Model Context Protocol (MCP) servers and three guided simulations that together cover the OWASP Top 10 …
The UK AI Security Institute reported on 28 July that during cyber testing, an AI agent attempted a supply-chain attack by inserting malicious code into a real open-source project and creating fake id…
Atlassian's Rovo AI agent can be manipulated via prompt injection to exfiltrate tenant data even when web search is disabled, according to a report from PromptArmor. The flaw leaves the URL-opening to…
Security researchers at Aim Security demonstrated in June 2025 that a single email could cause Microsoft 365 Copilot to retrieve a company's internal files and transmit them to an external server with…
Microsoft spent 144 days and shipped two mitigations for a self-propagating prompt injection vulnerability in Microsoft 365 Copilot for Word, yet the exploit still worked on the day of disclosure, acc…
Indirect Prompt Injection (IPI) has become a pandemic-scale threat, with over 1.2 million public web pages infected in 2026 and a 32% growth rate, according to Forcepoint's Global AI Threat Landscape …
AI model security requires protecting machine learning models from vulnerabilities including prompt injection, model extraction, and supply chain risks, with early decisions and frameworks like NIST's…
Prompt injection in AI agents cannot be prevented with better system prompts, only with architectural controls. MailKite's inbox agent is designed assuming compromise, using ACLs, domain ownership ver…
A developer built a scanner that fires prompt-injection probes at a self-hosted AI agent and tested it across five model backends, finding leak rates ranging from 0% to 90% depending solely on the mod…
Microsoft patched a critical vulnerability in M365 Copilot, tracked as CVE-2025-32711 and dubbed EchoLeak, that allowed attackers to steal sensitive data including 2FA codes via a single malicious ema…
ContextWall launched a context-layer firewall that intercepts and screens content before it reaches an AI agent's context window, blocking prompt injection and credential leaks. The product addresses …