MCP 'design flaw' puts 200k servers at risk: Researcher
…indirectly injecting the command via the allowed command's arguments, for example -'npx -c
In the poison stage, the attacker’s goal is to place malicious inputs into locations where they will ultimately be processed by the AI model. Two primary techniques dominate: Direct prompt injection: The attacker is the user, and provides inputs via normal user interactions. Impact is typically scoped to the attacker’s session but is useful for probing behaviors. Indirect prompt injection: The attacker poisons data that the application ingests on behalf of other users (e.g., RAG databases, shared documents). This is where impact scales. Text-based prompt infection is the most common technique
Modeling Attacks on AI-Powered Apps with the AI Kill Chain Framework | NVIDIA Technical BlogImpact is where the attacker’s objectives materialize by forcing hijacked model outputs to trigger actions that affect systems, data, or users beyond the model itself. In AI-powered applications, impact happens when outputs are connected to tools, APIs, or workflows that execute actions in the real world: State-changing actions: Modifying files, databases, or system configurations. Financial transactions: Approving payments, initiating transfers, or altering financial records. Data exfiltration: Encoding sensitive data into outputs that leave the system (e.g., via URLs, CSS tricks, or API ca
Modeling Attacks on AI-Powered Apps with the AI Kill Chain Framework | NVIDIA Technical BlogPersistence allows attackers to turn a single hijack into ongoing control. By embedding malicious payloads into persistent storage, attackers ensure their influence survives within and across user sessions. Persistence paths depend on the application’s design: Session history persistence: In many apps, injected prompts remain active within the live session. Cross-session memory: In systems with user-specific memories, attackers can embed payloads that survive across sessions. Shared resource poisoning: Attackers target shared databases (e.g., RAG sources, knowledge bases) to impact multiple
Modeling Attacks on AI-Powered Apps with the AI Kill Chain Framework | NVIDIA Technical Blog…indirectly injecting the command via the allowed command's arguments, for example -'npx -c
…commands," the Adversa AI Red Team said in a writeup provided ahead of publication to The Register . "But it didn't account for AI-generated commands from prompt injection – where a malicious…
…Cloudflare's answer to this particular problem is Agent Memory, a managed service for siphoning AI conversations when space is scarce, then injecting the data back on demand. "It gives AI agents…
…Ensure inference transits flow via Amazon Bedrock GovCloud or Google AI for Public Sector (Vertex). Block data gathering endpoints (Statsig/GrowthBook/Sentry) with a firewall. Block system prompt fingerprinting (via Bedrock, etc…
Cyber-crime AI recruiting biz Mercor says it was 'one of thousands' hit in LiteLLM supply-chain attack First public downstream victim, but won't be the last AI hiring startup Mercor…
How credential brokering prevents AI agents from compromising credentials via prompt injection
I often patch the system prompts on my Claude Code executable in order to make Claude more effective. Every time I upgrade, I ask Claude himself to dissect the new binary and look for problematic system prompts to modify…
I'm a recent grad from UMich and built AgentShield because agentic AI is moving fast but payment safety hasn't caught up. Agents are already being handed API keys, stablecoin wallets, and payment credentials - if one mis…
I kept noticing the same pattern: my AI coding agents solve the same problems over and over across sessions. Coding problems, version specific bugs and general guidelines, solved once through multiple agent interactions …
I use Claude everyday (no joke) and kept getting annoyed by the same thing: selecting text from responses with the mouse. Overshoot, re-select, copy, click input, paste. Especially bad in long conversations where you wan…
To show you the most relevant results, we’ve omitted some entries very similar to those already shown. Repeat the search with the omitted results included.