#PromptArmor
PromptArmor have a nasty description of a prompt injection attack against Google's new Antigravity AI IDE which can result in credentials (like AWS keys) being stolen by an attacker: www.promptarmor.com/resources/go...

My notes here: simonwillison.net/2025/Nov/25/...
Google Antigravity Exfiltrates Data
An indirect prompt injection in an implementation blog can manipulate Antigravity to invoke a malicious browser subagent in order to steal credentials and sensitive code from a user’s IDE.
www.promptarmor.com
November 25, 2025 at 9:00 PM
How an indirect prompt injection can manipulate Google's Antigravity IDE to invoke a malicious browser subagent and exfiltrate data; Google is working on a fix (PromptArmor)

Main Link | Techmeme Permalink
November 25, 2025 at 11:56 PM
『AIシステムのリスクを評価・監視するセキュリティ企業のPromptArmorが、Google Antigravityを介してユーザーデータを盗み出す攻撃手法が見つかったと報告しています。』

GoogleのAIコーディングツール「Google Antigravity」を悪用してデータを盗み出す攻撃手法が見つかる
gigazine.net/news/2025112...
GoogleのAIコーディングツール「Google Antigravity」を悪用してデータを盗み出す攻撃手法が見つかる
Googleは2025年11月、AIエージェント主導のコーディングツール「Google Antigravity」を発表しました。新たに、AIシステムのリスクを評価・監視するセキュリティ企業のPromptArmorが、Google Antigravityを介してユーザーデータを盗み出す攻撃手法が見つかったと報告しています。
gigazine.net
November 26, 2025 at 11:06 AM
Slack AI, an add-on assistive service available to users of Salesforce's team messaging service, is vulnerable to prompt injection, according to security firm PromptArmor. www.theregister.com/2024/08/21/s...
Slack AI can leak private data via prompt injection
Whack yakety-yak app chaps rapped for security crack
www.theregister.com
August 21, 2024 at 11:36 AM
『攻撃にはCopilot Coworkに特定の作業手順を覚えさせるためのファイルである「スキルファイル」が使用されるとのこと。』

Microsoft 365 CopilotのAIエージェント機能「Cowork」が勝手にファイルを流出させる可能性があるとセキュリティ企業が指摘
gigazine.net/news/2026052...
Microsoft 365 CopilotのAIエージェント機能「Cowork」が勝手にファイルを流出させる可能性があるとセキュリティ企業が指摘
Microsoft 365 Copilot Coworkにおいて「SharePointやOneDrive上のファイルが間接プロンプト注入によって流出する可能性がある」とAIセキュリティ企業のPromptArmorが報告しています。
gigazine.net
May 26, 2026 at 9:54 AM
Microsoft 365 CopilotのAIエージェント機能「Cowork」が勝手にファイルを流出させる可能性があるとセキュリティ企業が指摘
https://gigazine.net/news/20260526-microsoft-copilot-cowork-exfiltrates-files/
Microsoft 365 CopilotのAIエージェント機能「Cowork」が勝手にファイルを流出させる可能性があるとセキュリティ企業が指摘
Microsoft 365 Copilot Coworkにおいて「SharePointやOneDrive上のファイルが間接プロンプト注入によって流出する可能性がある」とAIセキュリティ企業のPromptArmorが報告しています。
gigazine.net
May 26, 2026 at 5:36 AM
--JSONFormatter and CodeBeautify expose snippets,
--PromptArmor demo'ed indirect prompt injection on Gemini,
--Polish police arrest man for spate of breaches,
--Comcast will pay $1.5m fine for exposing customer data,
--Hackers are breaching Barix boxes to send bogus radio broadcasts, 6/9
December 1, 2025 at 2:08 PM
Don't store passwords in slack, this exploit can steal anything in a private chat through prompt injection on their AI

Não comunique senhas no slack, invista em telepatia

- Learned through techtok.today
#bolhadev #tech #cybersec #bolhasec #privacy #infosec
September 11, 2024 at 12:04 PM
Google Antigravity Exfiltrates Data Google Antigravity Exfiltrates Data PromptArmor demonstrate a concerning prompt injection chain in Google's new Antigravity IDE : In this attack chain, we il...

#google #security #ai #prompt-injection #generative-ai #llms #gemini #exfiltration-attacks […]
Original post on simonwillison.net
simonwillison.net
November 25, 2025 at 9:57 PM
the companies using your private data to train AI are exposing that same private data to hackers using that same AI

who would have guessed the proliferation of AI made us all less secure without any real benefit? :D

promptarmor.substack.com/p/data-exfil...
Data Exfiltration from Slack AI via indirect prompt injection
Authors: PromptArmor
promptarmor.substack.com
August 21, 2024 at 3:12 PM
Avoiding access to private data, exposure to untrusted content, and an external communication path is difficult enough when working with AI. Integrations expands the scope of concern. PromptArmor recently looked at how ChatGPT and Claude work. The results are not reassuring.
Connecting AI agents to outside services explodes the risk radius
Connect all the things and watch what happens
www.theregister.com
July 20, 2026 at 10:16 PM
Microsoft 365 CopilotのAIエージェント機能「Cowork」が勝手にファイルを流出させる可能性があるとセキュリティ企業が指摘
https://gigazine.net/news/20260526-microsoft-copilot-cowork-exfiltrates-files/
Microsoft 365 CopilotのAIエージェント機能「Cowork」が勝手にファイルを流出させる可能性があるとセキュリティ企業が指摘
Microsoft 365 Copilot Coworkにおいて「SharePointやOneDrive上のファイルが間接プロンプト注入によって流出する可能性がある」とAIセキュリティ企業のPromptArmorが報告しています。
gigazine.net
May 26, 2026 at 9:03 PM
PromptArmor have a nasty description of a prompt injection attack against Google's new Antigravity AI IDE which can result in credentials (like AWS keys) being stolen by an attacker: https://www.promptarmor.com/resources/google-antigravity-exfiltrates-data

My notes here […]
Original post on fedi.simonwillison.net
fedi.simonwillison.net
November 25, 2025 at 9:04 PM
PromptArmor zeigt: Versteckter Text in einer PDF reicht, um über Atlassians KI-Agent Rovo Daten aus Jira und Confluence an externe Server zu schleusen. Der Angriff läuft ohne Nutzerbestätigung und hinterlässt keine sichtbaren Spuren – klassische Prompt-Injection mit realer Exfiltrati…
Versteckter Text in einem PDF reicht aus, um über Atlassians KI-Agent Rovo sensible Daten zu stehlen
Das Sicherheitsunternehmen PromptArmor zeigt, wie Atlassians KI-Agent Rovo über versteckte Anweisungen in PDFs sensible Daten aus Jira und Confluence unbemerkt an externe Server weiterleitet. Der Angriff erfordert keine Nutzerbestätigung u…
the-decoder.de
August 10, 2026 at 6:10 PM
According to PromptArmor, 931 of 2,517 connectors (37 percent) changed over the six-week period from mid-May to the end of June. So any security assumptions based on declared capabilities may no longer be valid. www.theregister.com/ai-and-ml/20...
Connecting AI agents to outside services explodes the risk radius
Connect all the things and watch what happens
www.theregister.com
July 22, 2026 at 12:06 PM
ChatGPT for Google Sheets Exfiltrates Workbooks
This attack does not require human-in-the-loop approvals, even when in settings the user has explicitly required human approval before ChatGPT edits workbooks. Overview Recently, OpenAI launched an AI extension for using ChatGPT in Google Sheets, which has accumulated over 185,000 downloads since its launch less than a month ago. This allows users to operate on their spreadsheets by interacting with an AI chatbot that lives in a sidebar, with the added benefit of drawing on data from ChatGPT connectors. A single indirect prompt injection attack triggered by a single benign user query can trigger all of the following effects at once: Exfiltration of many workbooks from across the victim’s account Display of an interactive phishing pop-up Overwriting the entire GPT sidebar with an attacker-controlled chatbot interface Attacker-controlled edits to your workbooks This attack occurs when any untrusted data source (e.g., from an imported sheet or ChatGPT connector) manipulates ChatGPT to run an attacker-controlled external script, which executes leveraging permissions the user has granted to the ChatGPT for Google Sheets extension. This vulnerability was responsibly disclosed to OpenAI. Despite multiple follow-ups, we received no communication beyond an automated reply to our initial disclosure. OpenAI's documentation fails to describe sensitive capabilities granted...
www.promptarmor.com
June 1, 2026 at 12:02 AM

New Slack AI flaw allows attackers to steal data from private channels via indirect prompt injection. Public channels can be used to leak sensitive info like API keys without direct access. Admins should consider restricting Slack AI's file ingestion.

#cybersecurity #infosec #Slack #AI
Data Exfiltration from Slack AI via indirect prompt injection
Authors: PromptArmor
promptarmor.substack.com
August 20, 2024 at 9:17 PM
OpenClaw AI Agents Leaking Sensitive Data in Indirect Prompt Injection Attacks
OpenClaw AI Agents Leaking Sensitive Data in Indirect Prompt Injection Attacks
Attackers can exploit insecure defaults and prompt injection vulnerabilities to turn normal agent behavior into a silent data-exfiltration pipeline. The core issue is not just confusing the AI model; it is manipulating the agent to steal sensitive information without requiring any user interaction. The most alarming demonstration comes from security firm PromptArmor. They revealed how an attacker can force an OpenClaw agent to leak data using a technique called indirect prompt injection combined with messaging app features. 0-Click Attack Chain An attacker hides malicious instructions inside content that the AI agent is expected to read. The agent processes the instructions and generates a URL controlled by the attacker. The agent appends sensitive data, such as API keys or private conversations, into the URL’s query parameters. The agent sends the malicious link back to the user via messaging platforms such as Telegram or Discord. Before the user even clicks the link, the messaging app automatically generates a link preview, silently fetching the URL and handing the sensitive data directly to the attacker. Because the messaging app’s auto-preview feature automatically triggers an outbound HTTP request , this creates a dangerous “no-click” attack. The agent’s response itself becomes the exfiltration event. According to CNCERT, OpenClaw’s default security posture poses significant enterprise risk by allowing agents to browse, execute tasks, or interact with local files. They categorized threats into four main areas: indirect prompt injection via external data, accidental destructive actions, malicious third-party activities, and the exploitation of known product vulnerabilities. OpenClaw is highly useful because it can do real work, but this autonomy makes compromises much more damaging. Messaging integrations where auto-preview behaviors create seamless pathways for data theft . Host and container access that allows prompt manipulation to translate into real-world system actions. A skills ecosystem where unvetted or malicious extensions can drastically widen the attack surface. Proximity to stored secrets, as agents often operate near operational credentials and tokens. As OpenAI recently highlighted, once an agent can retrieve external information and act autonomously, developers must assume that untrusted content will attempt to manipulate the system. Invaders reports that security teams should treat this issue as an architectural flaw rather than a simple AI bug. To protect deployments, organizations should implement the following steps: Disable auto-preview features in Telegram, Discord, Slack , and other channels where AI agents generate URLs. Isolate OpenClaw runtimes inside tightly controlled containers and keep default management ports off the public internet. Restrict unnecessary file system access and keep credentials out of plaintext configuration files. Install agent skills only from trusted sources and manually review third-party code before enabling it. Set up network monitoring to alert on agent-generated links pointing to unfamiliar domains or unexpected DNS lookups. Ultimately, the most important question for security teams is no longer whether an AI model can be manipulated , but rather what a manipulated agent is silently capable of doing next. Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories. The post OpenClaw AI Agents Leaking Sensitive Data in Indirect Prompt Injection Attacks appeared first on Cyber Security News .
cybersecuritynews.com
March 16, 2026 at 11:01 AM
GitHub Copilot CLI Executes Malware With Zero Approval. Your CI/CD Pipeline Would Have Caught It.
via Dev.to

https://flarestart.com/article/github-copilot-cli-executes-malware-with-zero-approval-your-cicd-pipeline-would-have-caught-it-20260228
#DevNews #Security
GitHub Copilot CLI Executes Malware With Zero Approval. Your CI/CD Pipeline Would Have Caught It.
Two days after GitHub Copilot CLI hit general availability, researchers at PromptArmor published a bypass: a crafted env curl command slips past the validator, downloads a payload from an attacker...
flarestart.com
February 28, 2026 at 10:00 AM
📝 Microsoft 365 Copilot「Cowork」の隠れたリスク——AIエージェントの自律性が生む「信頼の境界線」の崩壊

PromptArmorが指摘したCoworkのセキュリティ脆弱性は、単なるバグではなく、生成AIの自律化に伴う構造的な課題を露呈。企業のAI導入戦略に根本的な問いを投げかけている。

🔗 https://techscope365.com/660/

#Microsoft365 #AIセキュリティ #生成AI #AI #テクノロジー
May 26, 2026 at 3:50 PM