#promptinjection

2025-12-19

AI agent truy cập Gmail có thể bị tấn công Prompt Injection, dẫn đến rò rỉ dữ liệu nhạy cảm. Giải pháp: dùng Model Armor của Google Cloud để bảo vệ, lọc nội dung độc hại và bảo vệ riêng tư người dùng. Kết hợp Model Context Protocol (MCP) giúp tách biệt an toàn giữa LLM và dữ liệu. #AI #Security #Gmail #ModelArmor #PromptInjection #AIAnToan #BaoMatDuLieu #GoogleCloud #LLM #EthicalAI

dev.to/googleworkspace/securin

"From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows"

In this survey, we introduce the first unified, end-to-end threat model for LLM-agent ecosystems, spanning host-to-tool and agent-to-agent communications, formalize adversary capabilities and attacker objectives, and catalog over thirty attack techniques.

alphaxiv.org/abs/2506.23260v1

#research #AI #LLM #promptInjection #MCP #threatModel #taxonomy

Fig. 7: Example Workflows of Backdoor Attack Variants on an LLM-Powered Shopping Agent.
2025-12-16

Poetry as a cybersecurity threat? Yes, really.

A new paper shows “poetic jailbreaks” can bypass AI safety filters far more often than prose:

• 62% success with handwritten poems
• 43% with generated verse
• 8% with equivalent prose

Style, rhyme & metaphor confuse safety heuristics – the model “sees” a cute rhyme, not a threat.

Paper: arxiv.org/pdf/2511.15304

#AI #Cybersecurity #LLMs #PromptInjection #MachineLearning

NERDS.xyz – Real Tech News for Real Nerdsnerds.xyz@web.brid.gy
2025-12-15

CrowdStrike rolls out Falcon AI Detection and Response as AI prompts become the new attack surface

fed.brid.gy/r/https://nerds.xy

Cyber Tips Guidecybertipsguide
2025-12-15

AI-powered browsers are opening up a whole new attack surface: indirect prompt injection. Malicious instructions can hide in web pages, PDFs, emails—even after the “#” in a URL. Your browser’s AI assistant doesn't know better.

Chema Alonso :verified:chemaalonso@ioc.exchange
2025-12-15
Chema Alonso :verified:chemaalonso@ioc.exchange
2025-12-14

El lado del mal - Ciberseguridad e Inteligencia Artificial: Mi última charla de 2025 la tienes en Youtube elladodelmal.com/2025/12/ciber #IA #AI #Ciberseguridad #conferencias #charlas #Eventos #hacking #Privacidad #LLMs #PromptInjection #Jailbreak

three tigers in a trench coatthygrrr@tiggi.es
2025-12-12
2025-12-12

"Quicklines and Silly News - Weekly News Roundup 12/11/25" 👀👏

friendica.world/display/84b6ef

Teh AnKorage ☑️ankorage@fe.disroot.org
2025-12-12
"Quicklines and Silly News - Weekly News Roundup 12/11/25" 👀👏

!!! ALL HAIL THE VAN PANTHER !!!

!!! NOTE !!! Switched To Linux is, “written by a broad spectrum computer consultant to help people learn more about the Linux platform.” This account is a supporter of Switched To Linux and provides convenience posts of thumbnails art, videos and streams.

<<Posts may contain hashtags as content may pertain to many distributions and/or related material/topics. Posts may be reposted, boosted, shared, etc. by bots and/or other accounts and are done so at the discretion of the bots/accounts that perform those actions. This account is not responsible for the action(s) of those bots and/or accounts. Therefore, Offended Discretion is advised.>>

#SwitchedToLinux #Linux #Windows #Mac #Technology #Tech #AltTech #Privacy #Private #Security #Secure #FOSS #FreeAndOpenSource #FreeAndOpenSourceSoftware #FreeOpenSourceSoftware #YouTube #Odysee #Rumble #BitChute #Locals #Patreon #DLive #Twitch #AltTech #FactCheckTrue #Fediverse #SocialMedia #weeklynewsroundup #promptinjection #surveillance

!!! Tell us what you think by filling out a "SATISFACTION SURVEY or ABUSE/SPAM REPORT" form from Teh AnKorage !!!

https://cryptpad.disroot.org/form/#/2/form/view/elsOVQUrXAmGuer4kd75JhA3mNELuCj8cTjEUynrZZo/

\*Videos may take a considerable amount of time to post. If it is not present, it will be, soon(tm).

#YouTube -
https://www.youtube.com/@SwitchedtoLinux/videos

#Odysee -
https://odysee.com/@switchedtolinux:0?view=content

#Rumble -
https://rumble.com/c/SwitchedToLinux/videos

#Bitchute -
https://www.bitchute.com/channel/uf9hzD216LX0
Chema Alonso :verified:chemaalonso@ioc.exchange
2025-12-12

El lado del mal - GeminiJack: Indirect Prompt Injection en Google Gemini Enterprise elladodelmal.com/2025/12/gemin #Gemini #PromptInjection #Google #GeminiJack

ph00lt0ph00lt0
2025-12-11

Nothing new but a good article on by . While sql injections despite being common are mitigatable, prompt injections are not and are more dangerous.

ncsc.gov.uk/blog-post/prompt-i

2025-12-10

PromptPwnd – nie zgadniecie co się okazało po integracji LLM z GitHub Actions

Gdybyśmy otrzymywali dolara (no dobra – starczy 1 Polski Nowy Złoty) za każde nieudane połączenie AI z czymkolwiek, to właśnie pisalibyśmy ten tekst z pokładu jachtu. Tym razem “nowa” odsłona ataku została nazwana PromptPwnd (standardowo brakuje tylko logo i dżingla), a dotyka ona potoków CI/CD (ang. Continuous Integration/Continuous Development pipelines)....

#Aktualności #Ai #Cicd #Github #Llm #PromptInjection

sekurak.pl/promptpwnd-nie-zgad

2025-12-09

New AI-native threat: GeminiJack allowed zero-click exfiltration of Gmail, Docs & Calendar data in Google Gemini Enterprise + Vertex AI Search via indirect prompt injection in the RAG pipeline.

Analysis:
technadu.com/new-ai-native-thr

#GeminiJack #AINativeThreats #GoogleGemini #VertexAI #PromptInjection #RAGSecurity #CyberSecurity

New AI-Native Threat: Vulnerability in Google Gemini Enterprise and Vertex AI Search Allowed Stealing Gmail, Docs, and Calendar Data
Startupmacstartupmac
2025-12-09

Google details layered security for Chrome’s agentic AI, featuring a Gemini-powered "Critic."

Google is safeguarding Chrome's upcoming autonomous AI features with a "User Alignment Critic" model that vets every action for user safety, Origin Sets to prevent data leaks, and mandatory user confirmation for sensitive tasks like payments and banking access. These measures are designed to combat indirect prompt injection attacks.


9m

2025-12-08

"security teams and those owning the risk need to be aware that #promptinjection attacks will remain a residual risk, and cannot be fully mitigated with a product or appliance etc. It needs to be risk managed through careful design, build, and operation."

ncsc.gov.uk/blog-post/prompt-i

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst