Adversaries Hijacked AI Security Tools at Over 90 Organizations Via Prompt Injection
Threat actors exploited legitimate AI security tools at 90+ organizations using malicious prompt injection, with the next wave gaining write access to firewalls.
Threat actors exploited legitimate AI security tools at 90+ organizations using malicious prompt injection, with the next wave gaining write access to firewalls.
Oasis Security researchers discovered three chained flaws in Anthropic's Claude — including a prompt injection, Files API exfiltration path, and open redirect — enabling silent data theft through a Google Search ad.
Security researchers demonstrated that an autonomous AI agent successfully compromised McKinsey's internal AI system in less than two hours by exploiting prompt injection—a well-known but still widely unmitigated attack vector—raising urgent concerns about enterprise AI security.
Cybersecurity experts warn Moltbook, a social network for AI agents, poses prompt injection risks that could compromise thousands of agents simultaneously.
New enterprise security features protect against AI prompt injection and data exfiltration with deterministic controls for high-risk users.