AI Útoky

LLM Jacking

LLM jacking is an attack technique that cybercriminals use to manipulate and exploit an enterprise’s cloud-based LLMs (large language models).

Semantic Attack

Weaponizing Calendar Invites: A Semantic Attack on Google Gemini

HashJack Attack

HashJack Attack Targets AI Browsers and Agentic AI Systems

AI-targeted Cloaking Attack

OpenAI’s new browser Atlas falls for AI-targeted Cloaking Attack

Design Patterns for Securing LLM Agents against Prompt Injections 

Large Language Models (LLMs) are becoming integral components of complex software systems, where they serve as intelligent agents that can interpret natural language instructions, make plans, and execute actions through external tools and APIs

Context  Poisoning Jailbreak

Echo Chamber: A Context-Poisoning Jailbreak That Bypasses LLM Guardrails

Context Compliance Attack

(CCA), a jailbreak technique that involves the adversary injecting a "simple assistant response into the conversation history" about a potentially sensitive topic that expresses readiness to provide additional information

Policy Puppetry Attack

a prompt injection technique that crafts malicious instructions to look like a policy file, such as XML, INI, or JSON, and then passes it as input to the large language model (LLMs) to bypass safety alignments and extract the system prompt

Memory INJection Attack

(MINJA), which involves injecting malicious records into a memory bank by interacting with an LLM agent via queries and output observations and leads the agent to perform an undesirable action

Multi-Stage Phishing Attack Exploits Gamma

Attackers exploit Gamma in a multi-stage phishing attack using Cloudflare Turnstile and AiTM tactics to evade detection and steal Microsoft credentials.

Rules File Backdoor

New Vulnerability in GitHub Copilot and Cursor: How Hackers Can Weaponize Code Agents

MCP Prompt Injection

MCP Prompt Injection: Not Just For Evil

ComPromptMized

ComPromptMized: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Prompt Injection Attack

A prompt injection attack is a type of cyberattack where a hacker enters a text prompt into a large language model (LLM) or chatbot, which is designed to enable the user to perform unauthorized actions.