AI Útoky
LLM jacking is an attack technique that cybercriminals use to manipulate and exploit an enterprise’s cloud-based LLMs (large language models).
Weaponizing Calendar Invites: A Semantic Attack on Google Gemini
HashJack Attack Targets AI Browsers and Agentic AI Systems
OpenAI’s new browser Atlas falls for AI-targeted Cloaking Attack
Design Patterns for Securing LLM Agents against Prompt Injections
Large Language Models (LLMs) are becoming integral components of complex software systems, where they serve as intelligent agents that can interpret natural language instructions, make plans, and execute actions through external tools and APIs
Echo Chamber: A Context-Poisoning Jailbreak That Bypasses LLM Guardrails
(CCA), a jailbreak technique that involves the adversary injecting a "simple assistant response into the conversation history" about a potentially sensitive topic that expresses readiness to provide additional information
a prompt injection technique that crafts malicious instructions to look like a policy file, such as XML, INI, or JSON, and then passes it as input to the large language model (LLMs) to bypass safety alignments and extract the system prompt
(MINJA), which involves injecting malicious records into a memory bank by interacting with an LLM agent via queries and output observations and leads the agent to perform an undesirable action
Multi-Stage Phishing Attack Exploits Gamma
Attackers exploit Gamma in a multi-stage phishing attack using Cloudflare Turnstile and AiTM tactics to evade detection and steal Microsoft credentials.
New Vulnerability in GitHub Copilot and Cursor: How Hackers Can Weaponize Code Agents
MCP Prompt Injection: Not Just For Evil
ComPromptMized: Unleashing Zero-click Worms that Target GenAI-Powered Applications
A prompt injection attack is a type of cyberattack where a hacker enters a text prompt into a large language model (LLM) or chatbot, which is designed to enable the user to perform unauthorized actions.