Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment. The post Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini appeared first on SecurityWeek.

A new technique, dubbed ‘Cryptographic Context Injection,’ has reportedly demonstrated the ability to bypass AI safety guardrails in models such as Grok and Gemini. This method involves concealing malicious instructions within encrypted prompts, which are then decrypted only within a trusted execution environment, effectively circumventing the AI’s pre-processing safety mechanisms.
The core mechanism of Cryptographic Context Injection relies on the principle of late decryption. Instead of the AI model directly receiving and processing a plaintext prompt, it receives an encrypted payload. This payload contains the malicious instructions, but they remain unreadable and therefore undetectable by the AI’s initial safety filters and content moderation systems. The critical step occurs when this encrypted prompt is passed to a trusted execution environment (TEE), a secure area within a computer system.
Within the TEE, the encrypted prompt is decrypted. This decryption process reveals the hidden malicious instructions, which are then presented to the AI model as if they were part of a legitimate, unflagged input. Because the decryption happens within a secure, isolated environment, the AI’s external safety guardrails, designed to detect and block harmful content at the input stage, are bypassed entirely. The AI model then processes these newly revealed instructions without the benefit of its intended protective measures.
This class of attack highlights a significant challenge in securing advanced AI systems. Many AI safety guardrails operate by analyzing incoming prompts for keywords, patterns, or semantic indicators of harmful content. By encrypting the prompt, attackers can render these surface-level analyses ineffective. Products in the large language model (LLM) category, particularly those with sophisticated content filtering, could be vulnerable if they do not adequately account for scenarios where input processing is decoupled from initial safety checks.
The reported bypass affects Grok and Gemini, indicating that advanced AI models from different developers may share common architectural vulnerabilities or design patterns that this technique exploits. While specific details on the implementation of the trusted execution environment or the encryption scheme were not provided, the general concept suggests that any system relying on pre-processing safety filters could be susceptible if it can be induced to decrypt and execute instructions from an untrusted, encrypted source within a privileged context.
Mitigation for this type of vulnerability typically involves a multi-layered approach. Enhancing the security of trusted execution environments to prevent them from decrypting and passing potentially malicious content to the AI is crucial. Furthermore, AI safety mechanisms might need to evolve to incorporate post-decryption analysis within the TEE, or to verify the integrity and origin of decrypted prompts before allowing them to influence the AI’s behavior. Input validation and sanitization, even after decryption, remain critical.
This development underscores the ongoing arms race between AI developers and those seeking to exploit these powerful systems. As AI models become more integrated into critical applications, the methods for ensuring their safe and ethical operation must constantly adapt to novel attack vectors that circumvent traditional security paradigms. The focus shifts from merely filtering visible inputs to securing the entire processing pipeline, especially when sensitive operations like decryption occur.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed