← Back
VulnerabilityMalwarebytes Labs·1 hour ago

Encrypted instructions can fool AI assistants like Grok and Gemini

Researchers have demonstrated that prompt injection attacks can evade AI safety measures by concealing malicious instructions within encrypted text, potentially compromising guardrails in popular AI assistants. This technique highlights a significant vulnerability in current AI security implementations, allowing attackers to manipulate models like Grok and Gemini into executing unintended actions despite their built-in protections.

Read full article at Malwarebytes Labs

Related Articles

VulnerabilityInfosecurity Magazine·2 hours ago

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

Australian officials are warning TeamCity customers of an active exploitation campaign targeting a critical server vulnerability and urging immediate patching. The alert mirrors a similar warning previously issued by US government authorities, indicating the flaw poses a significant threat across international organizations.

VulnerabilityThe Register·2 hours ago

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

CISA has issued an emergency three-day patching deadline for a critical Oracle vulnerability that was disclosed in January and subsequently exploited in the wild, as evidenced by honeypot activity. The urgency reflects the flaw's severity and active exploitation, requiring U.S. government agencies to prioritize immediate remediation of this high-risk vulnerability.

VulnerabilityHelp Net Security·3 hours ago

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

At least 274 internet-facing Zimbra Collaboration Suite instances have been actively compromised by unknown attackers exploiting CVE-2026-73570, according to the Shadowserver Foundation. The vulnerability is a code injection flaw in ZCS that Synacor patched in version 10.1.20 released on July 20, 2026, leaving unpatched deployments at risk.

VulnerabilityThe Cyber Express·3 hours ago

Ledger Fixes Ethereum App Flaw as Disclosure Timeline Is Disputed

Ledger has patched a clear-signing vulnerability in its Ethereum app that could allow malicious applications to substitute transactions on device screens, but disputes with security firm TestMachine over the disclosure timeline and lack of public version documentation have left users unable to independently verify their protection status. The flaw, which TestMachine's AI scanner discovered on Ledger Flex and potentially affects Nano X, Nano S Plus, Stax, and Apex devices, has resulted in no independently confirmed fund theft as of late August 2026. The incident underscores the need for transparent security advisories with version identifiers and affected-device lists to help users confirm they have received patches.