Security
Safety, security and incidents · 3 stories
Researchers say GitHub Copilot CLI can be tricked into leaking .env secrets via encrypted prompts
On October 6 Adversa reported that Cryptographic Context Injection still worked against GitHub Copilot CLI as of October 1: in autopilot, one fetched page led the agent to read local files such as `.env.prod` and send them to an attacker in about 28 seconds.
SalesBleed: a public Salesforce lead form could zero-click leak CRM data through Agentforce
Zenity Labs showed that a prompt injection hidden in a Salesforce Web-to-Lead form could hijack Agentforce, query Accounts, and exfiltrate fields over DNS via an image URL, without the employee clicking anything. Salesforce has patched this chain.
OpenAI disrupts a campaign to extract its models' hidden reasoning, linking a core cluster to Moonshot AI
OpenAI says a coordinated 'adversarial distillation' campaign tried to extract its models' protected reasoning, peaking at 16,000 requests from more than 4,000 users in July, and attributes the core activity to people associated with Moonshot AI.