31.
32.
No Perfect Fix for AI Browser Prompt Injection Flaws
(darkreading.com)
33.
Atlassian Rovo Exfiltrates Data, Bypassing Controls
(news.ycombinator.com)
34.
Gemini Spark now has Chrome web-browsing capabilities
(engadget.com)
35.
Gemini Spark now works with Chrome, because giving your accounts to AI is a good idea
(androidauthority.com)
36.
After the Break-In: What Attackers Do Once They're Already Inside
(bleepingcomputer.com)
37.
38.
Document-borne AI worms can self-propagate through Copilot for Word
(news.ycombinator.com)
39.
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
(bleepingcomputer.com)
40.
ANSI escape injection in MCP servers: Hidden from humans, visible to AI
(news.ycombinator.com)
41.
42.
Show HN: ReasonGate- An explainable gate that blocks LLM prompt injection
(news.ycombinator.com)
43.
CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV
(news.ycombinator.com)
44.
Now, defenders are embracing the prompt injection, too
(arstechnica.com)
45.
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
(bleepingcomputer.com)
46.
Prismata: Confining cross-site prompt injection in web agents
(news.ycombinator.com)
47.
Factories Are Just Rooms
(news.ycombinator.com)
48.
Opera rolls out Paste Protect feature to fight ClickFix attacks
(bleepingcomputer.com)
49.
Claude helped uncover a ticketing flaw able to unlock free VIP festival passes
(androidauthority.com)
51.
New BioShocking attack manipulates AI browser into data theft
(bleepingcomputer.com)
52.
53.
What happened after 2k people tried to hack my AI assistant
(news.ycombinator.com)
54.
Computer use in Gemini 3.5 Flash
(news.ycombinator.com)
55.
Prompt Injection as Role Confusion
(news.ycombinator.com)
56.
Read this before you vibe-code another app
(theverge.com)
57.
58.
Copilot 'SearchLeak' Attack Allows 1-Click Data Theft
(darkreading.com)
59.