New "context bombing" techniques are being used to thwart malicious AI agents. These methods trick the AI into shutting down by feeding it misleading information, preventing it from carrying out harmful actions.

Researchers at Tracebit have developed a new defensive technique, dubbed "context bombing," that utilizes prompt injection attacks to disrupt malicious AI hacking agents. This method involves embedding specific, forbidden commands alongside sensitive data within a target environment, causing attacking large language models (LLMs) to shut down before they can inflict harm.
Context bombing leverages the inherent safety guardrails built into LLMs. When an attacking LLM encounters a command that violates these guardrails—such as instructions for developing biological weapons or references to politically sensitive events like the 1989 Tiananmen Square massacre—it triggers a refusal mechanism and ceases its current operations. This effectively neutralizes the AI agent's malicious intent.
Initial testing conducted by Tracebit in a simulated Amazon Web Services (AWS) environment demonstrated significant success. The researchers evaluated five prominent LLMs: Opus 4.8, Gemini 3.1 Pro, GLM 5.2, DeepSeek 4 Pro, and Kimi 2.6. Across 152 attack runs, planting a single context bomb string in a decoy secret reduced the rate at which agents achieved full account administrative access from 57 percent to 5 percent. The rate of complete compromise, which included establishing a persistent foothold, dropped from 36 percent to 1 percent.
Opus 4.8, identified as the most capable agent in these tests, went from achieving administrative access in 93 percent of runs to failing every single time when confronted with a context bomb. Averaged across all five models and 152 runs, the success rate for any attack path fell from 91 percent to 15 percent, and the average number of successful attack paths per run decreased from 1.53 to 0.16. Notably, no runs were able to complete an attack path without at least triggering a canary detection.
This defensive strategy builds upon Tracebit's earlier work from May, which introduced "canaries" – decoy AWS resources designed to alert defenders when their infrastructure is being probed by AI agentic adversaries. While these canaries provided an average eight-minute heads-up, the attacking models typically required 14 minutes to escalate to administrative control, leaving a narrow window for intervention. Context bombing aims to provide a more definitive stop to these attacks rather than just a warning.
Prompt injection has historically been used by attackers to manipulate LLMs into exfiltrating data or performing other harmful actions. For instance, security firm Socket previously uncovered an LLM agent that used prompt injections to direct target LLMs to provide instructions for building nuclear bombs or biological weapons, aiming to shut down AI-assisted malware analysis. Check Point researchers also discovered a similar malware prototype. Context bombing marks a significant shift, representing the first known instance where defenders have successfully turned this attack technique into a robust defense.
The underlying issue of prompt injection remains unresolved, forcing AI developers to rely on elaborate guardrails to prevent LLMs from going "off the rails." Context bombing offers defenders a novel way to leverage this persistent vulnerability to their advantage, effectively weaponizing the very problem that has plagued AI security.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed