FR
live
tag

#prompt-injection

OpenAI readies “o”, an always-on ChatGPT assistant built to handle email

On 27 September 2026, references to an always-on assistant called “o” briefly surfaced on OpenAI’s site, alongside a “-o” email suffix and a spot in the $100 Pro plan. Ahead of DevDay on 29 September, work out what an agent that reads and writes your mail does to your attack surface.

Gemini CLI now asks before editing your build files

On September 23, 2026, Google shipped Gemini CLI 0.61.0, which requires human confirmation before the agent edits a build file or runs a command shaped by untrusted content. Developers using a coding agent should update and leave those confirmations on: for now, they are the best defense against indirect prompt injection.

Encrypting your instructions is enough to bypass Grok and exfiltrate its users’ history

An Adversa researcher showed that encrypting malicious instructions with PBKDF2 and AES-256-GCM is enough to bypass Grok’s guardrails, which decrypt the payload and then execute it as their own tool output. xAI was told in June, and the assistant was still leaking users’ names, locations, and chat histories on August 20.

Atlassian Rovo Prompt Injection Sends Jira and Confluence Data to Attackers, One Path Still Unfixed

Two independent security research teams have demonstrated that Atlassian's Rovo AI assistant can be prompted to exfiltrate Jira and Confluence data to an attacker-controlled server. One attack path was fixed server-side on July 8, 2026 — the other remained open on August 8 with no fix announced. Atlassian Cloud admins must audit Rovo permissions immediately.

A silent AI worm spreads through Copilot for Word — and Microsoft can’t patch it

On July 28, 2026, researcher Håkon Måløy published the first public demonstration of a document-borne AI worm capable of silently altering financial reports and self-propagating through Microsoft Copilot for Word. After 144 days of coordinated disclosure and two attempted fixes — including a model upgrade to GPT-5.6 — the vulnerability class remains exploitable.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss