⤷ Title: SuperdEye: Go-ing Beyond AV/EDR with Indirect Syscalls
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Jan 2025 01:23:01 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #Indirect Syscalls
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Jan 2025 01:23:01 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #Indirect Syscalls
Penetration Testing Tools
SuperdEye: Go-ing Beyond AV/EDR with Indirect Syscalls
The purpose is to scan hooked NTDLL and retrieve the Syscall number to then do an indirect Syscall with it, thus allowing the bypass of AV/EDR
⤷ Title: Phishing LLMs: Hacking email summarizers
════════════════════════
𐀪 Author: m19o
════════════════════════
ⴵ Time: Sat, 08 Mar 2025 23:23:38 GMT
════════════════════════
⌗ Tags: #indirect_prompt_injection #hacking #penetration_testing #prompt_injection_attack #llm
════════════════════════
𐀪 Author: m19o
════════════════════════
ⴵ Time: Sat, 08 Mar 2025 23:23:38 GMT
════════════════════════
⌗ Tags: #indirect_prompt_injection #hacking #penetration_testing #prompt_injection_attack #llm
Medium
Phishing LLMs: Hacking email summarizers
Phishing LLMs is a thing, and I’m here to mess with email summarizers specifically. Call it AI red teaming, adversarial ML, or social…
⤷ Title: Data Leak in Microsoft Copilot: Emails Exfiltrated via Hidden Mermaid Diagram
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 25 Oct 2025 06:39:38 +0000
════════════════════════
⌗ Tags: #Data Leak #Vulnerability #cybersecurity #data leak #Indirect Prompt Injection #Mermaid #Microsoft 365 Copilot
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 25 Oct 2025 06:39:38 +0000
════════════════════════
⌗ Tags: #Data Leak #Vulnerability #cybersecurity #data leak #Indirect Prompt Injection #Mermaid #Microsoft 365 Copilot
Penetration Testing Tools
Data Leak in Microsoft Copilot: Emails Exfiltrated via Hidden Mermaid Diagram
A vulnerability in Microsoft 365 Copilot was exploited using hidden instructions and a Mermaid diagram to covertly exfiltrate a user's sensitive emails.
⤷ Title: Founding: The Next-Gen Loader Generator for Advanced Evasion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:21:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Bypass #Cybersecurity 2025 #ETW Blinding #Founding #Indirect Syscalls #Malware Evasion #Obfuscation #red teaming #Sandbox Evasion #shellcode
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:21:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Bypass #Cybersecurity 2025 #ETW Blinding #Founding #Indirect Syscalls #Malware Evasion #Obfuscation #red teaming #Sandbox Evasion #shellcode
Information Security News
Founding: The Next-Gen Loader Generator for Advanced Evasion
Founding is a tool that processes shellcode in .bin, .exe, or .dll formats, applying advanced obfuscation or encryption techniques to generate stealthy binaries with sophisticated execution method…
⤷ Title: RoguePilot: The Silent AI Hijacker Turning GitHub Issues into Repository Backdoors
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 07:36:33 +0000
════════════════════════
⌗ Tags: #Malware #AI security #GitHub Codespaces #GitHub Copilot #GITHUB_TOKEN #Indirect Prompt Injection #Microsoft Security #Orca Security #repository takeover #RoguePilot #supply chain attack #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 07:36:33 +0000
════════════════════════
⌗ Tags: #Malware #AI security #GitHub Codespaces #GitHub Copilot #GITHUB_TOKEN #Indirect Prompt Injection #Microsoft Security #Orca Security #repository takeover #RoguePilot #supply chain attack #Tech News 2026
Penetration Testing Tools
RoguePilot: The Silent AI Hijacker Turning GitHub Issues into Repository Backdoors
A critical vulnerability has been unearthed within GitHub Codespaces, enabling the illicit hijacking of repositories through the integrated
⤷ Title: From Theory to Threat: Hackers Are Now Weaponizing Web Pages to Brainwash AI Agents
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Mar 2026 00:07:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Ad Fraud #AI security #cybersecurity #IDPI #Indirect Prompt Injection #infosec #machine_learning #Prompt injection #threat intelligence #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Mar 2026 00:07:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Ad Fraud #AI security #cybersecurity #IDPI #Indirect Prompt Injection #infosec #machine_learning #Prompt injection #threat intelligence #Unit 42
Daily CyberSecurity
From Theory to Threat: Hackers Are Now Weaponizing Web Pages to Brainwash AI Agents
Unit 42 reveals the first real-world cases of Indirect Prompt Injection (IDPI), where hackers weaponize website content to bypass AI security filters.
⤷ Title: Hackers Use Hidden Website Instructions in New Attacks on AI Assistants
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 10:20:06 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #Claude Code #Copilot #Cyber Attack #Cybersecurity #GitHub #GitHub Copilot #Indirect Prompt Injection #IPI #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 10:20:06 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #Claude Code #Copilot #Cyber Attack #Cybersecurity #GitHub #GitHub Copilot #Indirect Prompt Injection #IPI #Vulnerability
Hackread
Hackers Use Hidden Website Instructions in New Attacks on AI Assistants
Cybersecurity researchers at Forcepoint uncover new indirect prompt injection attacks that use hidden website code to exploit AI assistants like GitHub Copilot.
⤷ Title: Prompt Injection Was Just the Beginning: Real AI Supply Chain Attacks Are Here in 2026
════════════════════════
𐀪 Author: Akansha Shukla
════════════════════════
ⴵ Time: Sun, 10 May 2026 22:07:43 GMT
════════════════════════
⌗ Tags: #vector_database #indirect_prompt_injection #supply_chain_security #api_security #ai_security
════════════════════════
𐀪 Author: Akansha Shukla
════════════════════════
ⴵ Time: Sun, 10 May 2026 22:07:43 GMT
════════════════════════
⌗ Tags: #vector_database #indirect_prompt_injection #supply_chain_security #api_security #ai_security
Medium
Prompt Injection Was Just the Beginning: Real AI Supply Chain Attacks Are Here in 2026
How indirect prompt injection, vector database poisoning, and agentic trust exploits are reshaping enterprise AI security.
⤷ Title: The Sabotage of Automation: Open-Source Project jqwik Poisoned Against AI Agents
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 31 May 2026 10:08:30 +0000
════════════════════════
⌗ Tags: #Technology #ANSI escape sequence terminal hiding #automated build log stream exploitation #Claude Code payload detection #indirect prompt injection software safety #Java testing dependencies boycott #jqwik hidden prompt injection #JUnit 5 platform alternative migration #Maven Central supply chain vulnerability #printMessageForCodingAgents source bytecode #protestware open source security risks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 31 May 2026 10:08:30 +0000
════════════════════════
⌗ Tags: #Technology #ANSI escape sequence terminal hiding #automated build log stream exploitation #Claude Code payload detection #indirect prompt injection software safety #Java testing dependencies boycott #jqwik hidden prompt injection #JUnit 5 platform alternative migration #Maven Central supply chain vulnerability #printMessageForCodingAgents source bytecode #protestware open source security risks
Information Security News
jqwik Hidden Prompt Injection Targets AI Coding Agents
Java testing library jqwik faces major developer backlash after version 1.10.0 deploys a hidden prompt injection payload aimed at tricking AI coding tools.
⤷ Title: The ChatGPhish Phenomenon: Indirect Prompt Injection via AI Summarization
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 04:13:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI summarization risk #ChatGPhish prompt injection #ChatGPT Markdown vulnerability #Indirect Prompt Injection #Permiso security research #web tracking pixel
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 04:13:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI summarization risk #ChatGPhish prompt injection #ChatGPT Markdown vulnerability #Indirect Prompt Injection #Permiso security research #web tracking pixel
Information Security News
ChatGPhish Prompt Injection: ChatGPT Phishing Risk
Discover the ChatGPhish prompt injection technique. Learn how malicious web summaries trick ChatGPT into rendering phishing links and tracking pixels.
⤷ Title: Prompt Injection — Demonstrate Indirect prompt injection in action
════════════════════════
𐀪 Author: Jose Praveen
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 22:31:01 GMT
════════════════════════
⌗ Tags: #prompt_injection #indirect_prompt_injection #tryhackme_writeup #ai_security #tryhackme
════════════════════════
𐀪 Author: Jose Praveen
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 22:31:01 GMT
════════════════════════
⌗ Tags: #prompt_injection #indirect_prompt_injection #tryhackme_writeup #ai_security #tryhackme
Medium
Prompt Injection — Demonstrate Indirect prompt injection in action
Begin your journey into understanding prompt injection right here!