All CosmicBytez Labs articles tagged #Data Exfiltration, across news, security advisories, how-to guides, and projects.
Researchers from the ASSET Research Group disclosed GhostSplice — a novel cross-channel trust fragmentation attack that splits malicious instructions across multiple MCP tool calls, bypassing safety filters to make AI coding agents like Cursor exfiltrate SSH keys, .env files, and source code.
Two independent security firms found that Atlassian's AI assistant Rovo is vulnerable to indirect prompt injection attacks that silently exfiltrate Jira and Confluence data to attacker-controlled servers — with no visible trace in the chat log.
American semiconductor giant Analog Devices has disclosed that an unauthorized party accessed some of its systems and exfiltrated certain files, though the company reports business operations remain unaffected.
A critical-severity SQL injection vulnerability (CVSS 9.6) in the Snowflake Snowpark Python SDK allows authenticated low-privilege users to execute SQL...
Researchers at Shandong University have demonstrated TrojPix, a covert channel attack that exfiltrates data from air-gapped computers by manipulating...
Microsoft uncovered a fake Perplexity AI Chrome extension that silently captured every search query and address bar keystroke, routing the data to an...
OpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts, restricting tool capabilities that could be exploited in prompt…
Recently observed Trigona ransomware attacks are using a bespoke command-line exfiltration tool to steal data from compromised environments faster and...
Security researchers disclosed critical flaws across three major AI platforms: Amazon Bedrock AgentCore's sandbox can be bypassed via DNS to exfiltrate...
China's CNCERT has warned that OpenClaw (formerly Clawdbot/Moltbot), the viral self-hosted AI agent, carries over 250 disclosed vulnerabilities including...