This week in the Wild West Roundup:
This week in the Wild West Roundup: A real Google Maps place page with tons of prompt injection in the comments. 'Comment and Control': Claude Code, Gemini CLI, GitHub Copilot Agents V...
21 chunks · 21 episodes
This week in the Wild West Roundup: A real Google Maps place page with tons of prompt injection in the comments. 'Comment and Control': Claude Code, Gemini CLI, GitHub Copilot Agents V...
This week in the Wild West Roundup. Paper: "A scan of approximately 2,000 MCP servers found all lacked authentication." Google DeepMind Researchers Map Web Attacks Against AI Agents. G...
This week in the Wild West Roundup: ChatGPT Data Leakage via a Hidden Outbound Channel in the Code Execution Runtime. A roundup: OpenClaw Security Report CrewAI Vulnerabilities Expose ...
This week in the Wild West roundup: Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website OpenClaw Agents Can Be Guilt-Tripped Into Self-Sabotage. "In a control...
This week's Wild West roundup: Claudy Day: an exfiltration that can happen entirely in a default Claude session. A rogue AI led to a serious security incident at Meta. Vulnerabili...
This week's Wild West roundup: Researchers Trick Perplexity's Comet AI Browser Into Phishing Scam in Under Four Minutes. ScamAgent: AI Agent Built by Researchers that Run Fully Au...
This week's Wild West roundup is a doozy: Clinejection: A GitHub Issue Title Compromised 4,000 Developer Machines. Simon's write up is also worth reading. Zenity Labs Discloses Pl...
This week in the Wild West roundup: A Facebook Alignment exec watched OpenClaw delete her email and couldn't stop it. Bloomberg: OpenClaw might be a security nightmare for Sam Altman. ...
This week's Wild West roundup: A Cline AI tool had a prompt injection attack that… installed OpenClaw on the user's system. ClawHub: the number 1 skill on OpenClaw was malware. Th...
Wild West roundup for this week: Data Exfil from Agents in Messaging Apps. Claude Desktop Extensions Exposes Over 10,000 Users to Remote Code Execution Vulnerability. ...
This week in the Wild West roundup: A Google Calendar Prompt Injection attack on Gemini. OpenAI's API logs can be exfiltrated by prompt injection. Bruce Schneier: Why AI Keeps Falling ...
This week in the Wild West roundup. Claude Cowork Exfiltrates Files. That was quick! It's like they didn't even try to protect it. "Here's a rusty chainsaw we just vibecoded, novice us...
This week in the Wild West roundup. Notion AI: Unpatched Data Exfiltration. IBM AI ('Bob') Downloads and Executes Malware. ZombieAgent prompt injection in ChatGPT. The prompt injection...
This week's Wild West roundup. Docker Fixes 'Ask Gordon' AI Flaw That Enabled Metadata-Based Attacks. Turning AI Safeguards Into Weapons with HITL Dialog Forging.
This week in the wild west roundup. PromptPwnd: Prompt Injection Vulnerabilities in GitHub Actions Using AI Agents. Prompt Injection inside of Github Actions. Ars: "Syntax hacking: Res...
This week in the wild west roundup. HashJack is a new indirect prompt injection technique. It takes advantage of the fact that the content after a hashtag in a URL won't lead to errors...
This week in the wild west roundup. Three official Claude extensions are vulnerable to remote code execution. Seven data exfiltration leakages found in ChatGPT. An Obsidian chat suppor...
This week in the wild west roundup: Brave demonstrates another prompt injection attack via images that affects most AI browsers. I Built an AI Prompt Injection Attack Demo : Here's Wha...
This week in the wild west roundup: A RCE where prompt injection can trivially get GitHub Copilot into YOLO mode. ASCII smuggling of prompt injection across various LLMs. Google refuse...
This week's wild west roundup, this time using LLMs incidentally in attack chains: Nx compromised: malware uses Claude code CLI to explore the filesystem zack_overflow: "A popular...