Check Point shows a planted instruction can make ChatGPT exfiltrate Gmail data through a covert channel between accounts.
A prompt injection flaw in Amazon's Kiro IDE can push sensitive local data to attackers when a poisoned project is…
Adversa AI shows how ciphertext hidden in a page can make xAI's Grok hand over chat details with no warning.
Varonis shows how one click on a crafted link can drain data from connected apps in Microsoft Copilot Personal.
Two firms found independent ways to turn Atlassian's Rovo assistant into a one-click data leak.
Two research teams found ways to make Atlassian's AI assistant ship Jira and Confluence data to attacker servers.
The SearchLeak chain weaponized three vulnerabilities in Microsoft 365 Copilot to exfiltrate sensitive data before server side sanitization could stop…
UNC6508 deployed InfiniteRed malware on REDCap servers at a North American medical research organization, remaining undetected for over a year…