oxhak on Nostr: Researchers have demonstrated a prompt-injection technique that hides malicious ...
Researchers have demonstrated a prompt-injection technique that hides malicious instructions inside encrypted data, raising concerns about AI assistants that browse the web, execute code or access private information. The attack, called Cryptographic Context Injection, persuades an AI agent to decrypt the data with its coding tools. The exposed instructions may then be treated as trusted context even though they came from an attacker.
Tests of two production AI agents produced different outcomes. Researchers said an ordinary request to summarize a page caused Grok to expose user’s chat data without a click or warning, while Gemini generated content it would normally refuse. They withheld full technical details, saying xAI had not acted after being notified in June 2026; Google has improved Gemini but has not fully closed the issue. Experts recommend limiting permissions, keeping credentials out of AI chats, and treating requests to decrypt, run scripts or open links as warning signs.
https://www.malwarebytes.com/blog/ai/2026/08/encrypted-instructions-can-fool-ai-assistants-like-grok-and-geminiPublished at
2026-08-25 12:06:42 UTCEvent JSON
{
"id": "732ba8ad02ba130f2f51c7bf235fb6b08efed322ab8857805e7e0e9e1696cbaa",
"pubkey": "81b26cb98224311ea520a9042bf9c7cc78d2725d0a99f9797afd9a8a35970aaa",
"created_at": 1787659602,
"kind": 1,
"tags": [],
"content": "Researchers have demonstrated a prompt-injection technique that hides malicious instructions inside encrypted data, raising concerns about AI assistants that browse the web, execute code or access private information. The attack, called Cryptographic Context Injection, persuades an AI agent to decrypt the data with its coding tools. The exposed instructions may then be treated as trusted context even though they came from an attacker.\n\nTests of two production AI agents produced different outcomes. Researchers said an ordinary request to summarize a page caused Grok to expose user’s chat data without a click or warning, while Gemini generated content it would normally refuse. They withheld full technical details, saying xAI had not acted after being notified in June 2026; Google has improved Gemini but has not fully closed the issue. Experts recommend limiting permissions, keeping credentials out of AI chats, and treating requests to decrypt, run scripts or open links as warning signs.\n\nhttps://www.malwarebytes.com/blog/ai/2026/08/encrypted-instructions-can-fool-ai-assistants-like-grok-and-gemini",
"sig": "dc5b436e67a06f82e3c82e630e688674398d5f389f92a616b52fcf808d29bb64ff4b14a020ad50b7c0dd6e864cfb1a7289d7ba751c6b76d1b497200afe924f26"
}