LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host

prompt injection

atlassianhigh

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Two security firms have identified vulnerabilities in Atlassian's Rovo assistant that could allow attackers to exfiltrate data from Jira and Confluence. One vulnerability, dubbed RovoBlast by Varonis Threat Labs, allowed attackers to trick Rovo into sending data to an external server via a malicious link. Atlassian has confirmed this issue is fixed server-side. The second vulnerability, found by PromptArmor, involved injecting malicious instructions into content Rovo processes, enabling data exfiltration without explicit user approval. The status of this second vulnerability remains unconfirmed after its initial disclosure.

ai

Prompt Injection Attacks Disrupt AI Hacking Agents

New "context bombing" techniques are being used to thwart malicious AI agents. These methods trick the AI into shutting down by feeding it misleading information, preventing it from carrying out harmful actions.

ai securityhigh

CrowdStrike Uncovers New Prompt Injection Techniques

CrowdStrike has identified and cataloged 18 new prompt injection techniques, expanding their taxonomy to over 200 distinct methods. These new techniques, including Trigger-Activated Rule Addition and Algorithmic Payload Decomposition, highlight the evolving sophistication of attacks against AI systems. The company emphasizes the need for enhanced AI threat modeling, red teaming, detection engineering, and runtime visibility to combat these emerging threats.

ai security

​​What’s new in Microsoft Security: June 2026

Microsoft is enhancing its security offerings with a focus on AI and agent protection. New features include 'Codename MDASH,' an AI-powered system for discovering and remediating complex software vulnerabilities across environments. Additionally, Microsoft Defender now extends endpoint protection to local AI agents, detecting and blocking threats like prompt injection attempts targeting tools such as GitHub Copilot CLI and Claude Code.

ai

AI threats in the wild: The current state of prompt injections on the web

Google's Threat Intelligence teams have analyzed the prevalence of indirect prompt injection (IPI) attacks on the public web. Their research indicates that while sophisticated IPI attacks are not yet widespread, there is a growing trend of experimentation by threat actors. The observed attacks range from harmless pranks and SEO manipulation to more concerning attempts at data exfiltration and system destruction, though current implementations are often simplistic.

ai

Google Workspace’s continuous approach to mitigating indirect prompt injections

Google is detailing its ongoing efforts to combat indirect prompt injection attacks against its Workspace AI features, like Gemini. This type of attack manipulates AI behavior by inserting malicious instructions into the data or tools the AI uses, potentially without direct user interaction. Google employs a continuous improvement strategy, utilizing both human and automated red-teaming exercises to discover and defend against emerging threats.