Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
wunderwuzzi23
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
wunderwuzzi23
16d ago
Part of the attack happens via the readme in the zip file, which is something the agent reads and follows (or better said in this attack, it does explicitly not follow those instructions for safety reasons, but decides to do something else)
2.
▲
by
wunderwuzzi23
1mo ago
One of the latest mitigations is to make sure that a URL an agent visits has been indexed by a search engine crawler. At least that is what OpenAI does now in ChatGPT. That makes sure that not a large amount of private data is leaked in one
3.
▲
Copirate 365: Plundering in the Depths of Microsoft Copilot (CVE-2026-24299)
(embracethered.com)
8 points
by
wunderwuzzi23
2mo ago
|
1 comments
4.
▲
by
wunderwuzzi23
2mo ago
Nice. A BASIC for game development takes me back to AMOS on the Commodore Amiga. https://en.wikipedia.org/wiki/AMOS_(programming_language)
5.
▲
A Framework for Frontier AI and the Dawning of a New Age
(demishassabis.substack.com)
5 points
by
wunderwuzzi23
2mo ago
|
0 comments
6.
▲
by
wunderwuzzi23
7mo ago
Correct. Good to see this get more coverage. Check out my research about unfurling in common messenger apps and also mitigations here: https://embracethered.com/blog/posts/2023/ai-injections-thre... And here
7.
▲
by
wunderwuzzi23
8mo ago
Agreed. In December I reported a data exfil in OpenAI Agent Builder and it was also closed as Not Applicable, so it's probably still there. It's also unclear if anyone from OpenAI even ever saw the report. I don't know. Maybe
8.
▲
by
wunderwuzzi23
8mo ago
Claude (generally, even non Cowork mode) is vulnerable to exfil via their APIs, and Anthropic's response was that you should click the stop button if exfiltration occurs. This is a good example of the Normalization of Deviance in AI by
9.
▲
by
wunderwuzzi23
8mo ago
Relevant prior post, includes a response from Anthropic: https://embracethered.com/blog/posts/2025/claude-abusing-net...
10.
▲
by
wunderwuzzi23
9mo ago
Excited! It's such a great event. I'm currently on a plane towards Hamburg and will be speaking on Day 2. "Agentic ProbLLMs - Exploiting AI Computer-Use and Coding Agents" https://events.ccc.de/congress&#
11.
▲
by
wunderwuzzi23
9mo ago
In case some of you find it entertaining. When MCP came out I had a flashback to COM/DCOM days, like IDispatch and list/tools. So, I built an MCP server that can host any COM server. :) Now, AI can launch and work on Excel, Outloo
12.
▲
The Normalization of Deviance in AI
(embracethered.com)
7 points
by
wunderwuzzi23
10mo ago
|
0 comments
13.
▲
by
wunderwuzzi23
10mo ago
Cool stuff. Interestingly, I responsibly disclosed that same vulnerability to Google last week (even using the same domain bypass with webhook.site). For other (publicly) known issues in Antigravity, including remote command execution, see
14.
▲
by
wunderwuzzi23
10mo ago
It still is. plus there are many more issue. i documented some here: https://embracethered.com/blog/posts/2025/security-keeps-goo...
15.
▲
by
wunderwuzzi23
10mo ago
The system prompt contains a lot more information about you. Just ask it to print all information under User Interaction Metadata. More details here: https://embracethered.com/blog/posts/2025/chatgpt-how-does-
16.
▲
by
wunderwuzzi23
11mo ago
Good point. Few thoughts I would add from my perspective: - The model is untrusted. Even if prompt injection is solved, we probably still would not be able to trust the model, because of possible backdoors or hallucinations. Anthropic recen
17.
▲
Claude will send your data to crims if they ask it nicely
(theregister.com)
10 points
by
wunderwuzzi23
11mo ago
|
0 comments
18.
▲
by
wunderwuzzi23
11mo ago
It gets even worse with LLMs and agents. Many LLMs can interpret invisible Unicode Tag characters as instructions and follow them (eg invisible comment or text in a GitHub issue). I wrote about this a few times, here a recent example with G
19.
▲
by
wunderwuzzi23
11mo ago
Great point. It's actually possible for one agent to "help" another agent to run arbitrary code and vice versa. I call it "Cross-Agent Privilege Escalation" and described in detail how such an attack might look like
20.
▲
Cross-Agent Privilege Escalation: When Agents Free Each Other
(embracethered.com)
2 points
by
wunderwuzzi23
1y ago
|
0 comments
21.
▲
by
wunderwuzzi23
1y ago
Thanks for sharing! I'm actually the person the Ars Technica article references. :) For recent examples check out my Month of AI bugs with of a focus on coding agents at https://embracethered.com/blog/posts/20
22.
▲
by
wunderwuzzi23
1y ago
Much longer actually, Bing Chat in Edge came out more than 2+ years ago.
23.
▲
by
wunderwuzzi23
1y ago
I wrote about how ChatGPT memory and also the chat history work a while ago. Figured to share since it also includes prompts on how to dump the info yourself https://embracethered.com/blog/posts/2025/chatgpt-h
24.
▲
Month of AI Bugs 2025
(monthofaibugs.com)
3 points
by
wunderwuzzi23
1y ago
|
0 comments
25.
▲
by
wunderwuzzi23
1y ago
About that find command... Amazon Q Developer: Remote Code Execution with Prompt Injection https://embracethered.com/blog/posts/2025/amazon-q-developer...
26.
▲
by
wunderwuzzi23
1y ago
Also, lots of prompt injection vulnerabilities in Amazon Q: Remote Code Execution: https://embracethered.com/blog/posts/2025/amazon-q-developer... Leaking Developer Secrets with DNS: https://embrac
27.
▲
by
wunderwuzzi23
1y ago
Great work! Great name! I'm currently doing a Month of AI bugs series and there are already many lethal trifecta findings, and there will be more in the coming days - but also some full remote code execution ones in AI-powered IDEs. h
28.
▲
Exfiltrating Your ChatGPT Chat History and Memories with Prompt Injection
(embracethered.com)
3 points
by
wunderwuzzi23
1y ago
|
0 comments
29.
▲
by
wunderwuzzi23
1y ago
I thought the same, a possible change from past might be the detailed data leakage and attack explanations? Eg how I described here a while ago: https://x.com/wunderwuzzi23/status/1930899939737166075?s=46&...
30.
▲
by
wunderwuzzi23
1y ago
AWS issued a post and they talk about revoking and replacing a credential. So maybe the hacker was able to directly push? https://aws.amazon.com/security/security-bulletins/AWS-2025-...
More ›