Robuta

https://simonwillison.net/2022/Sep/12/prompt-injection/
Riley Goodside, yesterday: Exploiting GPT-3 prompts with malicious inputs that order the model to ignore its previous directions. pic.twitter.com/I0NVr9LOJq-...
prompt injection attacksgpt
https://www.news9live.com/technology/artificial-intelligence/openai-ai-browsers-prompt-injection-risk-warning-2914220
Dec 23, 2025 - OpenAI has warned that AI browsing agents like ChatGPT Atlas may always face the danger of prompt injection attacks, where hidden text on webpages or emails...
prompt injection attacksopenaiwarningbrowsersrisk
https://brave.com/blog/prompt-injection-flaw-opera-neon/
Attackers can embed malicious instructions in hidden HTML elements and other non-rendered markup that remains invisible to users but is fully accessible to the...
prompt injectionopera neonflawbrave
https://www.csoonline.com/article/4036868/black-hat-researchers-demonstrate-zero-click-prompt-injection-attacks-in-popular-ai-agents.html
Sep 11, 2025 - Researchers from Zenity have found multiple ways to inject rogue prompts into agents from mainstream vendors to extract sensitive data from linked knowledge...
prompt injection attacksblack hatresearchersdemonstratezero
https://adversa.ai/blog/gpt-4-hacking-and-jailbreaking-via-rabbithole-attack-plus-prompt-injection-content-moderation-bypass-weaponizing-ai/
Jul 21, 2025 - GPT-4 Jailbreak is what all the users were waiting for since the GPT-4 release. Hack GPT-4 Bypass GPT4. DAN Jailbreak for GPT-4
prompt injectiongptjailbreakhackingvia
https://simonwillison.net/2025/Nov/2/new-prompt-injection-papers/
Two interesting new papers regarding LLM security and prompt injection came to my attention this weekend. Agents Rule of Two: A Practical Approach to AI Agent...
prompt injectionnewpapersagentsrule
https://arstechnica.com/information-technology/2023/02/ai-powered-bing-chat-spills-its-secrets-via-prompt-injection-attack/
Feb 14, 2023 - By asking “Sydney” to ignore previous instructions, it reveals its original directives.
aipoweredbingchatspills
https://simonwillison.net/2023/May/2/prompt-injection-explained/
I participated in a webinar this morning about prompt injection, organized by LangChain and hosted by Harrison Chase, with Willem Pienaar, Kojin Oshiba (Robust...
prompt injectionexplainedvideoslidestranscript
https://www.theregister.com/2026/01/08/openai_chatgpt_prompt_injection/
Jan 8, 2026 - : Happy Groundhog Day!
prompt injectionopenaipatchesvuchatgpt
https://playtech.ro/2025/openai-admite-browserele-cu-agenti-ai-vor-ramane-o-tinta-pentru-prompt-injection/
Dec 24, 2025 - Ideea unui browser care „navighează” în locul tău, completează formulare, compară produse și trimite e-mailuri sună ca un pas firesc în evoluția...
openaicuvor
https://witness.ai/blog/blog-why-relying-on-ai-providers-isnt-enough-to-protect-against-prompt-injection/
Jul 9, 2025 - There are several reasons why depending solely on AI providers to solve vulnerabilities like prompt injection may not be enough.
prompt injectionprotect
https://www.claneo.com/de/blog/test-case-wie-einfach-lassen-sich-ki-systeme-beeinflussen-prompt-injection/
Dec 2, 2025 - Wir haben ChatGPT, Perplexity & Google AI auf Prompt Injection getestet. Ergebnis: Faktische Infos binnen 24h übernommen, Rankings geschützt. Alle...
prompt injectionim testwieki
https://www.bankinfosecurity.eu/how-prompt-injection-breaking-digital-forensics-norms-a-29988
Logs are where cybersecurity teams spot how and when the break in occurred. For a new type of attack, logs will be worthless - a condition that will especially
prompt injectiondigital forensicsbreakingnorms
https://dev.to/mahin101/advent-of-cyber-2025-day-8-writeup-prompt-injection-tryhackme-4db1
Jan 2, 2026 - 👉 Room Link LLM breakthrough have unlocked a new field of AI called Agentic AI! It can accomplish a... Tagged with tryhackme, promptengineering,...
adventcyberdayampwriteup
https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duo
Sep 9, 2025 - The Legit research team unearthed vulnerabilities in GitLab Duo.
prompt injectiongitlab duosource coderemoteleads
https://www.zerounoweb.it/techtarget/searchsecurity/ai-security-cybersecurity-protezione-intelligenza-artificiale/
Dec 15, 2025 - AI Security: come proteggere pipeline di dati, modelli e GenAI dagli attacchi cyber. La visione SentinelOne.
ai securityprompt injectionagentic soclaroadmap
https://www.malwarebytes.com/blog/news/2025/08/ai-browsers-could-leave-users-penniless-a-prompt-injection-warning
Aug 25, 2025 - Prompt injection attacks could be coming to an AI browser near you. Read on to understand what these attacks do and how to stay safe.
prompt injectionaibrowserscouldleave
https://www.activefence.com/blog/ai-browser-perplexity-prompt-injection-phishing
See an indirect prompt injection in Perplexity's AI-powered Comet browser, why it matters, and how to avoid it.
prompt injectioncometfliesindirect
https://winbuzzer.com/2025/12/23/openai-deploys-automated-attacker-to-harden-atlas-browser-admits-prompt-injection-is-unsolved-xcxwbn/
Dec 23, 2025 - OpenAI has deployed a new automated security testing system for ChatGPT Atlas, but has also conceded that prompt injection remains an "unsolved"...
openaideploysautomatedattackerharden
https://timkellogg.me/blog/2025/11/03/colors
prompt injectionmcpcolorsdealrisk
https://www.itmagazine.ch/artikel/86048/Neue_Prompt-Injection_macht_Links_zur_Gefahr_fuer_KI-Browser.html
Hashjack ist eine neue Variante von Prompt-Injection-Angriffen, bei der Angreifer schädliche Anweisungen hinter dem Rautezeichen in Links verstecken und so...
prompt injectionneuemachtlinkszur
https://www.techtarget.com/searchsecurity/tip/Types-of-prompt-injection-attacks-and-how-they-work
Mar 13, 2024 - Malicious actors use prompt injection techniques to exploit LLMs. Learn about four kinds of prompt injection attacks and how to prevent them.
prompt injection attackstypeswork
https://simonwillison.net/2023/Oct/14/multi-modal-prompt-injection/
GPT4-V is the new mode of GPT-4 that allows you to upload images as part of your conversations. It’s absolutely brilliant. It also provides a whole new set...
prompt injectionmultimodalimageattacks
https://futurism.com/artificial-intelligence/openai-browser-victim-prompt-injection-attacks
Oct 24, 2025 - Experts confirmed almost immediately that OpenAI's latest AI browser, dubbed Atlas, is "definitely vulnerable to prompt injection."
ai browseropenainewalreadyfalling
https://the-decoder.com/prompt-injection-gpt-3-has-a-serious-security-flaw/
Sep 17, 2022 - Twitter is running riot with a GPT-3 bot. But the underlying vulnerability could lead to major problems for applications with large language models that...
prompt injectionserious securitygptflaw
https://winbuzzer.com/2025/11/25/security-flaw-in-google-antigravity-ide-allows-data-exfiltration-via-prompt-injection-xcxwbn/
Nov 26, 2025 - According to security researchers, Google Antigravity allows data exfiltration via indirect prompt injection, bypassing default safety controls.
google antigravitydata exfiltrationsecurityflawai
https://josephthacker.com/ai/2025/11/24/prompt-injection-isnt-a-vulnerability.html
Is prompt injection a vulnerability or just a delivery mechanism?
prompt injectionvulnerabilityjoseph
https://www.itprotoday.com/powershell/securing-powershell-how-to-stop-prompt-injection-attacks-part-2
Aug 13, 2025 - The second part of this five-part series on stopping prompt injection attacks defines what a prompt injection attack is and provides a simple example of such...
prompt injection attackssecuringpowershellstoppart
https://www.timesofai.com/news/chatgpt-atlas-gets-security-update-to-stop-prompt-injection/
Jun 9, 2025 - OpenAI rolls out a major security update for ChatGPT Atlas, strengthening defenses against prompt injection attacks in its AI-powered browser.
chatgpt atlassecurity updateprompt injectiongetsstop
https://techcrunch.com/2025/12/22/openai-says-ai-browsers-may-always-be-vulnerable-to-prompt-injection-attacks/
Dec 22, 2025 - OpenAI says prompt injections will always be a risk for AI browsers with agentic capabilities, like Atlas. But the firm is beefing up its cybersecurity with an...
openaisaysbrowsersmayalways
https://simonwillison.net/2023/Dec/20/mitigate-prompt-injection/
I’m in the latest episode of RedMonk’s Conversation series, talking with Kate Holterhoff about the prompt injection class of security vulnerabilities: what...
prompt injectionrecommendationshelpmitigatelimit
https://www.itprotoday.com/powershell/securing-powershell-how-to-stop-prompt-injection-attacks-part-4
Aug 13, 2025 - The fourth part of this five-part series on stopping prompt injection attacks describes how dangerous such attacks can be.
prompt injection attackssecuringpowershellstoppart
https://simonwillison.net/2023/Nov/27/prompt-injection-explained/
A neat thing about podcast appearances is that, thanks to Whisper transcriptions, I can often repurpose parts of them as written content for my blog. One of...
prompt injectionexplainednovemberedition
https://www.techzine.eu/news/security/137488/openai-the-risk-of-prompt-injection-may-never-disappear/
Dec 23, 2025 - OpenAI argues that prompt injection will probably never disappear, but that a proactive response can significantly reduce the risk.
prompt injectionopenairiskmaynever
https://www.theregister.com/2025/10/28/ai_browsers_prompt_injection/
Oct 28, 2025 - Feature: Agentic features open the door to data exfiltration or worse
wide openprompt injectionaibrowsersattack
https://www.aikido.dev/blog/promptpwnd-github-actions-ai-agents
AI-driven GitHub Actions expose new prompt-injection supply chain vulnerabilities.
prompt injectiongithub actionsnew frontierinsidesupply
https://dev.to/brennan/breaking-ai-browser-defenses-is-easy-novel-prompt-injection-techniques-that-work-2fbj
Nov 3, 2025 - I discovered several novel prompt injection techniques that successfully bypass modern AI browser... Tagged with ai, vulnerabilities, webdev, javascript.
ai browserprompt injectionbreakingdefenseseasy
https://pangea.cloud/taxonomy/
Explore the Pangea Prompt Injection Taxonomy using the interactive web experience
prompt injectiontaxonomypangea
https://www.csoonline.com/article/3992845/prompt-injection-flaws-in-gitlab-duo-highlights-risks-in-ai-assistants.html
May 22, 2025 - Researchers managed to trick GitLab’s AI-powered coding assistant to display malicious content to users and leak private source code by injecting hidden...
prompt injectiongitlab duoflawshighlightsrisks
https://www.buzzwebzine.fr/prompt-injection-attack-danger-navigateurs-ia/
Nov 2, 2025 - De Comet de Perlexity à Atlas d’OpenAI en passant par Opera Neon, nous sommes en train de basculer dans l’ère des navigateurs agentiques ou navigateurs...
prompt injectionquestcele
https://www.foxnews.com/tech/openai-admits-ai-browsers-face-unsolvable-prompt-attacks
Jan 4, 2026 - Prompt injection attacks against AI browsers cannot be fully eliminated, OpenAI admits in new blog post about ChatGPT Atlas security risks.
prompt injection attacksopenaiadmitsfully
https://simonwillison.net/2025/Apr/9/mcp-prompt-injection/
As more people start hacking around with implementations of MCP (the Model Context Protocol, a new standard for making tools available to LLM-powered systems)...
model context protocolprompt injectionsecurityproblems
https://academy.hackthebox.com/course/preview/prompt-injection-attacks
This module comprehensively introduces one of the most prominent attacks on large language models (LLMs): Prompt Injection. It introduces prompt injection ba...
prompt injection attackscoursehtbacademy
https://mlsecops.com/podcast/beyond-prompt-injection-ais-real-security-gaps
Exploring AI security gaps, Gavin Klondike discusses prompt injections, trust boundaries, and security measures in AI applications on the MLSecOps Podcast.
prompt injectionbeyondrealsecuritygaps
https://www.ibm.com/think/topics/prompt-injection
In prompt injection attacks, hackers manipulate generative AI systems by feeding them malicious inputs disguised as legitimate user prompts.
prompt injectionattackibm
https://brave.com/blog/comet-prompt-injection/
The attack we developed shows that traditional Web security assumptions don't hold for agentic AI, and that we need new security and privacy architectures...
browser securityprompt injectionagenticindirectperplexity
https://cyberscoop.com/uk-warns-ai-prompt-injection-unfixable-security-flaw/
Dec 8, 2025 - The comments echo many in the research community who have said the flaw is an inherent trait of generative AI technology.
ukcyberagencywarnsllms
https://hiddenlayer.com/innovation-hub/indirect-prompt-injection-of-claude-computer-use/
Nov 14, 2024 - Discover the security risks of Anthropic's Claude Computer Use, including indirect prompt injection attacks.
prompt injectioncomputer useindirectclaude
https://xite.ai/blogs/the-invisible-threat-in-ai-conversations-understanding-prompt-injection/
Nov 28, 2025 - Learn how prompt injection can disrupt AI tools, cause data exposure, and undermine trust. Get practical guidance and steps to build safer workflows at work.
prompt injection attackshidden riskbehindai
https://www.itprotoday.com/powershell/securing-powershell-how-to-stop-prompt-injection-attacks-part-1
Aug 13, 2025 - Learn how seemingly innocent PowerShell database scripts can become dangerous security vulnerabilities when left unprotected against prompt injection attacks.
prompt injection attackssecuringpowershellstoppart
https://dev.to/mrasadatik/ai-browsers-and-prompt-injection-the-new-cybersecurity-frontier-41eo
Nov 5, 2025 - Picture this: You’re browsing a news site on your shiny new AI-powered browser, let’s call it... Tagged with ai, cybersecurity, llm, news.
prompt injectionaibrowsersnewcybersecurity
https://the-decoder.de/prompt-injection-gpt-3-hat-eine-schwere-sicherheitsluecke/
Sep 17, 2022 - Twitter tobt sich an einem GPT-3-Bot aus. Doch die zugrundeliegende Sicherheitslücke könnte zu größeren Problemen bei Anwendungen mit großen...
prompt injectiongpthateine
https://simonwillison.net/2023/May/11/delimiters-wont-save-you/
Prompt injection remains an unsolved problem. The best we can do at the moment, disappointingly, is to raise awareness of the issue. As I pointed out last...
prompt injectionsave
https://www.csoonline.com/article/4053107/ai-prompt-injection-gets-real-with-macros-the-latest-hidden-threat.html
Sep 24, 2025 - Attackers are evolving their malware delivery tactics by weaponing malicious prompts embedded in document macros to hack AI systems.
ai promptgets realinjectionmacroslatest
https://arstechnica.com/security/2025/02/new-hack-uses-prompt-injection-to-corrupt-geminis-long-term-memory/
Feb 12, 2025 - There's yet another way to inject malicious prompts into chatbots.
prompt injectionnewhackusescorrupt
https://www.knostic.ai/prompt-injection-defense-solution
Defend against prompt injection attacks. Knostic stops malicious prompts, protects context, and ensures safe AI use.
prompt injectiondefense
https://simonwillison.net/2023/Apr/14/worst-that-can-happen/
Activity around building sophisticated applications on top of LLMs (Large Language Models) such as GPT-3/4/ChatGPT/etc is growing like wildfire right now. Many...
prompt injectionworsthappen
https://josephthacker.com/hacking/2025/10/20/metanarrative-prompt-injection.html
Metanarrative prompt injections in AI security and its implications.
prompt injectionjoseph
https://pangea.cloud/blog/ethical-hackers-mindset-leads-to-victory-in-pangea-ai-challenge/
The Pangea Blog | Discover how ethical hacker won Pangea's AI $10,000 Prompt Injection Challenge, revealing key lessons for enterprise AI security
ethical hackerai promptwinspangeainjection
https://www.numerama.com/cyberguerre/2152201-ils-menent-des-cyberattaques-par-les-mots-quest-ce-quune-injection-de-prompt.html
Jan 4, 2026 - L’attaque par injection de prompt attire particulièrement l’attention des experts. Elle fait partie d'une nouvelle vague de risques cyber, liés à...
injectiondepromptiafonctionnement
https://www.csoonline.com/article/4088682/wie-chatgpt-sich-selbst-eine-prompt-injection-zufugt.html
Nov 12, 2025 - Sicherheitsforscher haben neue Wege gefunden, wie sich die Standardfunktionen von ChatGPT durch indirekte Prompt Injections missbrauchen lassen, um sensible...
prompt injectioncso onlinewiechatgptsich
https://www.itprotoday.com/powershell/securing-powershell-how-to-stop-prompt-injection-attacks-part-5
Aug 13, 2025 - The final part of this five-part series describes how to defend against a prompt injection attack.
prompt injection attackssecuringpowershellstoppart
https://us.norton.com/blog/ai/prompt-injection-attacks
Dec 11, 2025 - Learn what prompt injection attacks are, their risks, and how to protect your data.
prompt injectionattackexamplesincluded
https://www.infosecurity-magazine.com/news/hashjack-indirect-prompt-injection/
Nov 30, 2025 - A new threat dubbed “HashJack” could enable attackers to booby trap websites when they interact with AI browsers
prompt injectionindirectwebsitesmagazine
https://hiddenlayer.com/innovation-hub/prompt-injection-attacks-on-llms/
Jan 8, 2025 - HiddenLayer explains various forms of abuses and attacks against LLMs from jailbreaking, to prompt leaking and hijacking.
prompt injection attacksllms
https://www.csoonline.com/article/4069887/github-copilot-prompt-injection-flaw-leaked-sensitive-data-from-private-repos.html
Oct 8, 2025 - Hidden comments in pull requests analyzed by Copilot Chat leaked AWS keys from users’ private repositories, demonstrating yet another way prompt injection...
github copilotprompt injectionsensitive dataflawleaked