Adversa AI researchers disclosed a technique called Cryptographic Context Injection that bypasses AI safety filters by encrypting malicious instructions in AES-256-GCM, which the targeted models decrypt and execute without triggering guardrails. Demonstrated attacks against xAI's Grok and Google's Gemini included a zero-click exploit exfiltrating Grok users' full chat histories and prompting Gemini to generate dangerous instructions and reproduce its own system prompts. The vulnerability exposes a fundamental structural weakness in content-based guardrails, which cannot inspect payloads that only become readable after the model has already decided to trust them, with limited vendor engagement and no coordinated disclosure path at Google due to their AI reward program exclusions.
Microsoft disclosed a maximum-severity remote code execution vulnerability in Entra ID (CVE-2026-69836, CVSS 10.0) caused by unsafe deserialization, then reversed its advisory's "Exploited: Yes" designation to "No" without explanation a day later, leaving enterprises uncertain whether active attacks occurred. The company server-side patched the flaw affecting its cloud identity platform that underpins Microsoft 365, Azure, and thousands of federated applications, but declined to disclose detection methods, scope of exposure, or evidence supporting either exploitation claim. The reversal raises questions about transparency in vulnerability reporting, particularly for cloud services where only the provider holds forensic facts needed to assess materiality under emerging SEC and CISA disclosure frameworks.