This week in the Wild West Roundup:
This week in the Wild West Roundup: A real Google Maps place page with tons of prompt injection in the comments. 'Comment and Control': Claude Code, Gemini CLI, GitHub Copilot ...
27 chunks · 27 episodes
This week in the Wild West Roundup: A real Google Maps place page with tons of prompt injection in the comments. 'Comment and Control': Claude Code, Gemini CLI, GitHub Copilot ...
This week in the Wild West Roundup. Paper: "A scan of approximately 2,000 MCP servers found all lacked authentication." Google DeepMind Researchers Map Web Attacks Against AI A...
This week in the Wild West Roundup: ChatGPT Data Leakage via a Hidden Outbound Channel in the Code Execution Runtime. A roundup: OpenClaw Security Report CrewAI Vulnerabilities...
This week in the Wild West roundup: Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website OpenClaw Agents Can Be Guilt-Tripped Into Self-Sabotage. "In a...
This week's Wild West roundup: Claudy Day: an exfiltration that can happen entirely in a default Claude session. A rogue AI led to a serious security incident at Meta. Vul...
This week's Wild West roundup: Researchers Trick Perplexity's Comet AI Browser Into Phishing Scam in Under Four Minutes. ScamAgent: AI Agent Built by Researchers that Run ...
This week's Wild West roundup is a doozy: Clinejection: A GitHub Issue Title Compromised 4,000 Developer Machines. Simon's write up is also worth reading. Zenity Labs Disc...
This week in the Wild West roundup: A Facebook Alignment exec watched OpenClaw delete her email and couldn't stop it. Bloomberg: OpenClaw might be a security nightmare for Sam ...
This week's Wild West roundup: A Cline AI tool had a prompt injection attack that… installed OpenClaw on the user's system. ClawHub: the number 1 skill on OpenClaw was mal...
Wild West roundup for this week: Data Exfil from Agents in Messaging Apps. Claude Desktop Extensions Exposes Over 10,000 Users to Remote Code Execution Vulnera...
This week in the Wild West roundup: A Google Calendar Prompt Injection attack on Gemini. OpenAI's API logs can be exfiltrated by prompt injection. Bruce Schneier: Why AI Keeps ...
This week in the Wild West roundup. Claude Cowork Exfiltrates Files. That was quick! It's like they didn't even try to protect it. "Here's a rusty chainsaw we just vibecoded, n...
This week in the Wild West roundup. Notion AI: Unpatched Data Exfiltration. IBM AI ('Bob') Downloads and Executes Malware. ZombieAgent prompt injection in ChatGPT. The prompt i...
This week's Wild West roundup. Docker Fixes 'Ask Gordon' AI Flaw That Enabled Metadata-Based Attacks. Turning AI Safeguards Into Weapons with HITL Dialog Forging.
This week in wild west round up: Google's Agentic AI wipes user's entire HDD without permission in catastrophic failure. "Cache wipe turns into mass deletion event as agent...
This week in the wild west roundup. PromptPwnd: Prompt Injection Vulnerabilities in GitHub Actions Using AI Agents. Prompt Injection inside of Github Actions. Ars: "Syntax hack...
This week in the wild west roundup. HashJack is a new indirect prompt injection technique. It takes advantage of the fact that the content after a hashtag in a URL won't lead t...
This week in the wild west roundup. Three official Claude extensions are vulnerable to remote code execution. Seven data exfiltration leakages found in ChatGPT. An Obsidian cha...
This week's AI security wild west round up. A 'tainted memories' vulnerability in ChatGPT Atlas allows persistent malicious injection. ChatGPT Atlat has a omnibox prompt injection att...
This week in the wild west roundup: Brave demonstrates another prompt injection attack via images that affects most AI browsers. I Built an AI Prompt Injection Attack Demo : He...