Grok Vulnerable to Chat History Exfiltration via Cryptographic Context Injection
A new 'Cryptographic Context Injection' attack uses encrypted on-page data to trick xAI's Grok into exfiltrating user chat history.
A new 'Cryptographic Context Injection' attack uses encrypted on-page data to trick xAI's Grok into exfiltrating user chat history.
Opening an untrusted repo in Cursor on Windows auto-runs a git.exe planted at the repo root — zero-click RCE. Here's the flaw and what to lock down.
BioShocking hijacks an agentic browser's task-reward loop to exfiltrate credentials — here's why prompt guardrails fail and what capability boundary actually stops it.
A new 'GitSpawn' vulnerability allows malicious Git repositories to execute arbitrary code via AI coding agents, requiring immediate patches for tools like Claude Code and Cursor.
Active exploitation of critical vulnerabilities in Langflow and Ruby on Rails allows attackers to execute code and compromise AI development environments.
A now-patched API vulnerability in major LLMs allowed attackers to replay encrypted session logs to steal internal model reasoning and user secrets.