Prompt Injection
Ongoing coverage on Prompt Injection.
Latest coverage
A Pro Se Litigant Buried Prompt Injections in Court Papers, Gambling the Judge Would Let AI Do the Reading
A pro se litigant attempted to use prompt injection by hiding commands in court filings, intending for an AI to read them. However, the court had no AI in use, and a human staff member discovered the hidden text. The judge deemed this a serious litigation abuse, revoking the litigant's electronic filing access and requiring all future submissions to be on paper. This marks the first documented prompt injection attack aimed at a U.S. court and the first sanction for such an attempt.
Invisible One-Point Text in a PDF Can Siphon Jira Data Out Through Atlassian’s Rovo
Security firm PromptArmor has detailed a vulnerability in Atlassian's AI agent, Rovo, allowing for data exfiltration from Jira and Confluence through specially crafted PDFs. The attack uses invisible, one-point text within a PDF to inject commands that cause Rovo to fetch and send sensitive ticket and document data to an attacker-controlled URL. PromptArmor reported the vulnerability to Atlassian in May 2026 but received no response, leading to public disclosure.
Claude Code turns Auto Mode on by default as Anthropic targets rubber-stamped approvals
Anthropic is enabling 'Auto Mode' by default for its Claude Code AI agent starting August 14th for Pro, Max, and Team plan users. This change aims to streamline developer workflows by automatically approving routine actions, with the AI only pausing for potentially dangerous or irreversible operations. An independent audit found zero prompt injection successes against Claude Code in Auto Mode, while OpenAI's GPT-5.6 Sol in a similar mode experienced a 5.83% success rate.
AI worms? In your Copilot PC? According to this AI researcher, it's more likely than you think
An AI researcher has detailed a cybersecurity vulnerability where an AI worm could spread through Microsoft Copilot for Word via prompt injection. Attackers can hide malicious instructions within documents, which Copilot may interpret and replicate into new documents, creating a chain reaction. While Microsoft has attempted mitigations, the vulnerability remains reproducible, prompting advice to disable Copilot in Word or avoid the AI agent altogether.