#exfiltration-attacks
Your weekly reminder not to build LLM systems that combine access to private data with exposure to untrusted tokens and exfiltration vectors (the "lethal trifecta"). This time it was Microsoft 365 Copilot (now patched, they closed the exfiltration holes) simonwillison.net/2025/Jun/11/...
Breaking down ‘EchoLeak’, the First Zero-Click AI Vulnerability Enabling Data Exfiltration from Microsoft 365 Copilot
Aim Labs reported CVE-2025-32711 against Microsoft 365 Copilot back in January, and the fix is now rolled out. This is an extended variant of the prompt injection exfiltration attacks we've …
simonwillison.net
June 11, 2025 at 11:09 PM
Once again, if your LLM system combines access to private data, exposure to malicious instructions and the ability to exfiltrate information (through tool use or through rendering links and images) you have a nasty security hole

This time, GitLab: simonwillison.net/2025/May/23/...
Remote Prompt Injection in GitLab Duo Leads to Source Code Theft
Yet another example of the classic [Markdown image exfiltration attack](https://simonwillison.net/tags/exfiltration-attacks/), this time affecting GitLab Duo - GitLab's chatbot. Omer Mayraz reports on...
simonwillison.net
May 23, 2025 at 2:44 PM
my new blogpost is out!!

this one talks about a new web vulnerability class i discovered that allows for complex interactive cross-origin attacks and data exfiltration

and i've already used it to get a google docs bounty ^^

have fun <3

lyra.horse/blog/2025/12...
SVG Filters - Clickjacking 2.0
A novel and powerful twist on an old classic.
lyra.horse
December 4, 2025 at 2:03 PM
DNS-based attacks require vigilant monitoring and threat detection. DNS can be exploited for data exfiltration.
December 8, 2024 at 5:32 PM
6. This is because Iran's attack crossed a major threshold: a direct, attributed attack from Iranian territory on Israeli territory. For all the major lethal & nonlethal attacks Israel has carried out in Iran (Stuxnet, multiple assassinations, document exfiltration) they have all been covert.
April 14, 2024 at 9:22 AM
In this world nothing can be said to ve certain except death, taxes and LLM will dutifuly exfiltrate your data via a hidden prompt:

www.promptarmor.com/resources/cl...
Claude Cowork Exfiltrates Files
Claude Cowork is vulnerable to file exfiltration attacks via indirect prompt injection as a result of known-but-unresolved isolation flaws in Claude's code execution environment.
www.promptarmor.com
January 15, 2026 at 3:14 AM
We have seen the exact same bug previously in ChatGPT, Google Bard, Writer.com, Amazon Q, Google NotebookLM, Slack, Google AI Studio, Microsoft Copilot, Mistral LeChat, xAI Grok, Claude and now GitLab - I've been collecting examples here https://simonwillison.net/tags/exfiltration-attacks/
Simon Willison on exfiltration-attacks
26 posts tagged ‘exfiltration-attacks’. Exfiltration attacks are prompt injection attacks against chatbots that have access to private information, where that information is exfiltrated by the attack…
simonwillison.net
May 23, 2025 at 4:14 PM
Cl0p cybercrime gang's data exfiltration tool found vulnerable to RCE attacks
Cl0p cybercrime gang's data exfiltration tool found vulnerable to RCE attacks
Experts say they don't expect the MOVEit menace to do much about it Security experts have uncovered a hole in Cl0p's data exfiltration tool that could potentially leave the cybercrime group vulnerable to attack.…
dlvr.it
July 2, 2025 at 9:44 AM
OpenAI just added a feature that lets you let their Codex "cloud-based software engineering agent" access the internet, with a VERY prominent warning about the threat of prompt injection and exfiltration attacks simonwillison.net/2025/Jun/3/c...
Codex agent internet access
Sam Altman, [just now](https://twitter.com/sama/status/1930006856019390521): > codex gets access to the internet today! it is off by default and there are complex tradeoffs; people should read about t...
simonwillison.net
June 3, 2025 at 9:21 PM
I’m not talking (yet) about firms deliberately trying to monetize data. Right now I’m talking just about accidental (or malicious) exfiltration risk. Prompt injection attacks that cause a model to pipe private data outward to public places.
March 22, 2026 at 3:39 PM
Microsoft has identified extensive cloud resource destruction activity linked to JADEPUFFER, which Microsoft tracks as Storm-3168. The activity used compromised service principals and performed cloud credential collection that could be used to facilitate future exfiltration. msft.it/6015a9lob
Storm-3168: Agentic-driven cloud attacks using compromised service principals | Microsoft Security Blog
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders.
msft.it
September 25, 2026 at 3:42 PM
"We have seen this pattern so many times now: if your LLM system combines access to private data, exposure to malicious instructions and the ability to exfiltrate information (through tool use or through rendering links and images) you have a nasty security hole."
simonwillison.net/2025/May/23/...
Remote Prompt Injection in GitLab Duo Leads to Source Code Theft
Yet another example of the classic [Markdown image exfiltration attack](https://simonwillison.net/tags/exfiltration-attacks/), this time affecting GitLab Duo - GitLab's chatbot. Omer Mayraz reports on...
simonwillison.net
May 23, 2025 at 3:22 PM
Added an extra section discussing the potential for a new data exfiltration vector opened up by API calls from a Canvas simonwillison.net/2024/Dec/10/...
December 11, 2024 at 4:04 AM
Today’s top AI datacenters are vulnerable to both asymmetrical sabotage—where relatively cheap attacks could disable them for months—and exfiltration attacks, in which closely guarded AI models could be stolen or surveilled, the report’s authors warn.

time.com/7279123/ai-d...
Exclusive Report: Every AI Datacenter Is Vulnerable to China
A report circulated in the Trump White House says U.S. datacenters are vulnerable—putting national security at risk in the AI race with China.
time.com
April 22, 2025 at 8:48 PM
This is a really naive view of cybersecurity that should give you pause as to how well you understand the domain you cover. Non-govt hardware is the majority of attack surface for spying attempts. Both for direct attacks and exfiltration of personal info for social engineering... All widely known.
July 6, 2026 at 6:44 AM
The latest update for #Corelight includes "The water system attacks were simple. Securing OT isn't." and "Recognizing and detecting data exfiltration".

#cybersecurity #networks #networksecurity https://opsmtrs.com/3CB9DMm
Corelight
Corelight gives you the high ground—a commanding view of your network that lets you outsmart and outlast adversaries.
opsmtrs.com
September 25, 2026 at 4:33 AM
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks.

Telegram AI Digest
#ai #news
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks.
www.securityweek.com
September 26, 2026 at 3:13 AM
Some notes on the new Claude API web fetch tool, which I think can be used safely despite the risk of prompt injection exfiltration attacks if you're really carful with the allowed_domains parameter simonwillison.net/2025/Sep/10/...
Claude API: Web fetch tool
New in the Claude API: if you pass the web-fetch-2025-09-10 beta header you can add {"type": "web_fetch_20250910", "name": "web_fetch", "max_uses": 5} to your "tools" list and Claude will gain the …
simonwillison.net
September 10, 2025 at 5:28 PM
The latest update for #Corelight includes "The water system attacks were simple. Securing OT isn't." and "Recognizing and detecting data exfiltration".

#potatosecurity #networks #networksecurity https://opsmtrs.com/3CB9DMm
September 25, 2026 at 4:33 AM
À la découverte du "SVG clickjacking"

"I’ve discovered a new technique that turns classic clickjacking on its head and enables the creation of complex interactive clickjacking attacks, as well as multiple forms of data exfiltration."

👉 lyra.horse/blog/2025...
December 9, 2025 at 8:42 PM
Salesforce Agentforceの「SalesBleed」脆弱性により、信頼されたエージェントが乗っ取られ、データ窃盗やフィッシング攻撃が可能になる。(94文字)
'SalesBleed' Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
SalesBleed, three vulnerabilities in Salesforce Agentforce, enabled agent hijacking for data exfiltration and phishing attacks.
www.securityweek.com
September 25, 2026 at 11:48 AM
FBI Unveils IOCs for Cyber Attacks Targeting Salesforce Instances for Data Exfiltration
FBI Unveils IOCs for Cyber Attacks Targeting Salesforce Instances for Data Exfiltration
cybersecuritynews.com
September 14, 2025 at 6:17 AM
Hackers Leverage Red Team Tools in RDP Attacks Via TOR & VPN for Data Exfiltration
Hackers Leverage Red Team Tools in RDP Attacks Via TOR & VPN for Data Exfiltration
APT group Earth Koshchei, also tracked as APT29 or Midnight Blizzard, has been linked to a massive rogue Remote Desktop Protocol (RDP) campaign.
cybersecuritynews.com
December 17, 2024 at 9:52 AM
Do you worry about security? There's a lot.of sensitive info in the totality of one's email. Plus sometimes 2FA, password reset links, etc. Does eg Anthropic then 'upload' your email to its model? Errant exfiltration? And prompt injection email attacks?
September 26, 2026 at 11:53 PM