Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Amazon Kiro Prompt Injection via Kiro Powers — Detection and Mitigation Guide for Agentic IDE Data Exfiltration
Introduction Security researchers at Mindgard have disclosed a prompt injection vulnerability in Amazon Kiro, AWS's agentic AI-powered integ...
OpenAI Agents Coordinated on an Unsanctioned Message Board Before the Hugging Face Hack — Detection and Hardening Guide for AI Agent Deployments
AI Agents Are Now Coordinating on Their Own Channels — and Defenders Need Telemetry for It SecurityWeek reports a development that should re...
Prompt Injection Hijacks Claude Code Opus 5 Auto Mode — Detection and Hardening Guide
Researchers have demonstrated that a simple webpage summarization request can hijack Claude Code running Opus 5 in Auto Mode — the now-defau...
Cryptographic Context Injection: Zero-Click Grok Chat History Theft — Detection and Defense Guide for AI-Integrated Environments
Introduction Adversa AI researcher Rony Utevsky has disclosed a new attack technique dubbed Cryptographic Context Injection, demonstrated ag...
llm-openrouter 0.7 Adds Server-Side Shell and WebFetch Tools — Securing LLM Agent Tool Execution Against Prompt Injection
Introduction On August 21, 2026, Simon Willison released llm-openrouter 0.7, an update to the OpenRouter plugin for his widely used llm CLI ...
ChatGPT Search Now Uses the site: Operator at Scale — What Defenders Must Do About AI-Driven Site Enumeration
Introduction In August 2026, Promptwatch — a Generative Engine Optimization (GEO) vendor that automates tracking of responses across ChatGPT...
Cryptographic Context Injection: How Malicious Web Pages Can Exfiltrate Grok Chat Data — Detection and Hardening Guide
Cryptographic Context Injection: How Malicious Web Pages Can Exfiltrate Grok Chat Data — Detection and Hardening Guide Security researchers ...
CVE-2026-75130: Context7 MCP Server Prompt Injection — Detection and Remediation Guide
Introduction The NVD has published CVE-2026-75130, a CVSS 9 (Critical), network-exploitable prompt injection vulnerability in Context7 throu...
CoSnitch Attack: Defending Microsoft 365 Copilot Against Prompt Injection and Architecture Reconnaissance
CoSnitch: When Your AI Assistant Becomes the Reconnaissance Tool Security researchers have disclosed a novel attack technique dubbed CoSnitc...