Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2707+ Articles
165+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
18 articles

#Prompt Injection

All CosmicBytez Labs articles tagged #Prompt Injection, across news, security advisories, how-to guides, and projects.

  • NewsAug 11, 2026

    Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

    Researchers from the ASSET Research Group disclosed GhostSplice — a novel cross-channel trust fragmentation attack that splits malicious instructions across multiple MCP tool calls, bypassing safety filters to make AI coding agents like Cursor exfiltrate SSH keys, .env files, and source code.

  • NewsAug 11, 2026

    Vague Task, Total Access: When AI Delegation Becomes a Security Risk

    As enterprise AI agent deployments accelerate, a dangerous pattern is emerging: agents assigned loosely defined tasks are being granted broad, persistent access to organizational systems — creating an attack surface that traditional identity and access controls were never designed to handle.

  • NewsAug 9, 2026

    Flaws in Google ADK for Python Unlock Agent-to-Agent Attack

    Researchers at Pillar Security documented the first confirmed real-world agent-to-agent exploitation in a production system, targeting Google's Agent Development Kit for Python — downloaded over 90 million times. A prompt injection via a malicious pull request could hijack a high-privilege maintainer AI agent and compromise the CI/CD pipeline.

  • NewsAug 8, 2026

    Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

    Two independent security firms found that Atlassian's AI assistant Rovo is vulnerable to indirect prompt injection attacks that silently exfiltrate Jira and Confluence data to attacker-controlled servers — with no visible trace in the chat log.

  • NewsAug 8, 2026

    Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data

    Researchers discovered a parameter-to-prompt injection flaw in Atlassian Rovo AI that allowed a single malicious link click to exfiltrate Confluence API keys, Jira data, and files from Microsoft 365 and Google Workspace integrations.

  • NewsAug 7, 2026

    AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

    A new class of prompt injection embedded in "Ask AI" buttons on commercial websites silently writes biased recommendations into users' AI assistant memory — no malware, no credentials, just a weaponized URL parameter.

  • NewsJul 30, 2026

    The Network Has Become the Control Plane for AI Security

    As AI agents, copilots, and LLM-powered applications proliferate across enterprise environments, traditional packet-inspection firewalls are blind to the threats they introduce. Check Point argues the network layer — the universal chokepoint for all AI traffic — must evolve into an intent-aware enforcement platform.

  • SecurityJul 12, 2026

    CVE-2026-61445: PraisonAI AICoder Arbitrary File Write and Command Injection via LLM Tool Calls

    A CVSS 9.9 critical vulnerability in PraisonAI before 4.6.78 allows attackers to write files to arbitrary filesystem locations and execute arbitrary OS...

  • SecurityJul 12, 2026

    CVE-2026-61447: PraisonAI CodeAgent Remote Code Execution via Unsandboxed Python Execution

    A CVSS 10.0 critical vulnerability in PraisonAI before 1.6.78 allows attackers to achieve remote code execution by injecting malicious prompts that...

  • NewsJul 11, 2026

    'Ghostcommit' Hides Prompt Injection in Images to Fool AI Agents and Steal Secrets

    Security researchers have demonstrated 'Ghostcommit,' a technique that embeds prompt injection payloads inside PNG images to bypass AI code review tools...

  • NewsJul 9, 2026

    AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

    Researchers at the AI Now Institute have demonstrated a 'Friendly Fire' attack that tricks AI coding agents — including Claude Code, Gemini CLI, and...

  • NewsJul 3, 2026

    Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution

    Two critical vulnerabilities (CVE-2026-50548, CVE-2026-50549) dubbed DuneSlide allow zero-click prompt injection attacks to escape Cursor IDE's sandbox...

  • NewsJun 30, 2026

    Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks

    Security researchers have found that classic Bash shell techniques — some dating back decades — can bypass the safeguards in most open-source AI coding...

  • NewsJun 6, 2026

    New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration

    OpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts, restricting tool capabilities that could be exploited in prompt…

  • NewsApr 19, 2026

    Microsoft, Salesforce Patch AI Agent Data Leak Flaws

    Prompt injection vulnerabilities in Salesforce Agentforce and Microsoft Copilot would have allowed unauthenticated attackers to exfiltrate sensitive CRM...

  • SecurityMar 28, 2026

    CVE-2026-30304 — AI Code Safe Command Execution Bypass

    A critical flaw in AI Code's automatic terminal command execution design allows unsafe commands to bypass the model-based safety judgement and be...

  • NewsMar 14, 2026

    OpenClaw AI Agent Flaws Enable Prompt Injection, 1-Click

    China's CNCERT has warned that OpenClaw (formerly Clawdbot/Moltbot), the viral self-hosted AI agent, carries over 250 disclosed vulnerabilities including...

  • NewsFeb 17, 2026

    Microsoft Discovers 'AI Recommendation Poisoning' via Chatbot Prompts

    Microsoft's Defender team tracked over 50 unique prompt injection payloads from 31 companies using 'Summarize with AI' buttons to manipulate chatbot...