Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIGoogle Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
Google removed three AI agent workflows from its Agent Development Kit (ADK) Python repository after Pillar Security discovered a critical vulnerability. The flaw allowed malicious actors to exploit a public GitHub issue to manipulate a triage agent, triggering a privileged code-fixing agent through prompt injection. The attack leveraged the bot's collaborator status to execute unauthorized comman
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
Anthropic's Claude Opus 5 demonstrates significant improvements in resisting prompt injection attacks, reducing successful attack rates to 2.0% within 15 attempts compared to 5.5% for its predecessor. The model substantially outperforms competing AI models, including GPT 5.6 variants which show 10x higher vulnerability rates, establishing Opus 5 as the most robust model evaluated on the IPI benchm
AIMicrosoft Copilot for Word Can Copy Hidden Prompts Into New Documents
A security researcher disclosed a vulnerability in Microsoft 365 Copilot for Word where hidden instructions embedded in documents can manipulate AI-generated content and self-propagate into newly created files. The technique, reported to Microsoft 144 days prior to public disclosure, demonstrates how malicious prompts can persist across multiple document generation sessions, potentially compromisi
AICopilot 'SearchLeak' Attack Allows 1-Click Data Theft
A critical three-stage 'SearchLeak' attack vulnerability in Microsoft Copilot has been patched that enabled one-click data theft through AI prompt-injection techniques. The attack exploited hidden URLs and other variables to extract sensitive information, representing an emerging class of security threats targeting AI-powered enterprise tools.
AINew Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
Security researchers from Imperva and Varonis have independently demonstrated critical vulnerabilities in OpenClaw, a widely-used self-hosted AI agent, showing it can be manipulated to execute malicious code and expose sensitive information. The attacks exploit the agent's processing of seemingly benign inputs like vCards, shared contacts, and location data, allowing attackers to embed hidden inst
AINew ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration
OpenAI has introduced Lockdown Mode for ChatGPT personal accounts to mitigate data exfiltration risks from prompt injection attacks. The feature targets users and organizations handling sensitive data by restricting certain tools and capabilities. It is available across all personal account tiers including Free, Go, Plus, and Pro.
AIMalicious Notifications Could Trick Google Gemini Users
Security researchers have identified a prompt injection vulnerability in Google Gemini's voice assistant that allows attackers to embed malicious commands within system notifications. This flaw creates opportunities for social engineering attacks by exploiting the AI assistant's processing of notification content, potentially compromising user security and data integrity.
AIChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
Cybersecurity researchers at Permiso Security have identified a vulnerability dubbed 'ChatGPhish' in OpenAI's ChatGPT that exploits the platform's trust in Markdown links and images. The flaw enables attackers to execute prompt injection attacks and conduct phishing campaigns by manipulating how ChatGPT's web interface renders Markdown content. This vulnerability highlights emerging security risks
