{"results":[{"item":{"id":"86612afd6762c17d4872683b05eec7c255ab76db","incidentId":"bdbb2217dec2ecb80e3a2829647822c112c88ede","title":"What is Prompt Injection? How it Works and How to Prevent It | CloudSEK","summary":"CloudSEK's knowledge-base page titled 'What is Prompt Injection? How it Works and How to Prevent It' is framed as an explainer on prompt injection attacks against LLMs, covering how the attack works and prevention measures. The retrieved page body contained only cookie-consent boilerplate, with no substantive technical content available for analysis.","whyItMatters":"Prompt injection remains a core threat class for LLM-based systems, and educational explainers help defenders understand and mitigate it, though this particular page yielded no analyzable technical detail.","threatTypeTags":["prompt-injection"],"affectedTechTags":["llm"],"threatActor":null,"relevanceScore":0.5,"severityScore":0.1,"sources":[{"sourceId":"firecrawl-search","title":"What is Prompt Injection? How it Works and How to Prevent It | CloudSEK","link":"https://www.cloudsek.com/knowledge-base/prompt-injection"}],"sourceItemIds":["8997b5348553610623134c118a15f21faf1d0c05"],"publishedAt":"2026-07-17T04:45:00.006Z","firstReportedAt":"2026-07-17T04:45:00.006Z","curatedAt":"2026-07-17T05:08:34.879Z","itemType":"analysis","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://www.cloudsek.com/knowledge-base/prompt-injection","domain":"cloudsek.com","slug":null,"tier":"unknown","title":"What is Prompt Injection? How it Works and How to Prevent It | CloudSEK","pageTitle":"What is Prompt Injection? How it Works and How to Prevent It | CloudSEK"}]},"score":0.2664698799568529},{"item":{"id":"028244b4d01b9ef26ed0984b04c769290f1b3ee1","incidentId":"9249969308f10e91922369e0c3b0e4f6bfc17984","title":"People are using prompt injection to trick Meta's AI into handing over Instagram accounts - Neowin","summary":"Attackers used prompt injection against Meta's AI support assistant on Instagram, sending crafted messages instructing it to link an attacker-controlled email to a target account, causing the AI to send password reset links to the attacker and bypassing 2FA. The exploit was reportedly active in the wild for months, compromising thousands of accounts including a dormant Obama White House account before being patched.","whyItMatters":"It shows that AI agents with account-modifying privileges can be socially engineered via prompt injection to bypass authentication controls and hand over accounts at scale.","threatTypeTags":["prompt-injection","account-takeover","data-exfiltration"],"affectedTechTags":["llm","ai-agents"],"threatActor":null,"relevanceScore":0.95,"severityScore":0.85,"sources":[{"sourceId":"hn-search","title":"People are using prompt injection to trick Meta's AI into handing over Instagram accounts - Neowin","link":"https://www.neowin.net/news/people-are-using-prompt-injection-to-trick-metas-ai-into-handing-over-instagram-accounts/"}],"sourceItemIds":["50f2adde4b016b531a38b4f8765226dfb190a107"],"publishedAt":"2026-06-01T04:13:47.000Z","firstReportedAt":"2026-06-01T04:13:47.000Z","curatedAt":"2026-06-27T04:03:38.550Z","itemType":"incident","threatStatus":"unknown","contentClass":"threat","toolPosture":null,"toolCategory":null,"references":[]},"score":0.2642063166603288},{"item":{"id":"89d0852d491a84e50946aa4bf06c7fc054266754","incidentId":"846ccdf4101fd9b731f79df7a1ebaa31284554d1","title":"A Catalog of Prompt Injection Techniques | Blog | Archestra","summary":"A vendor blog catalogs ten basic prompt injection techniques including context ignoring, fake completion, payload splitting, token smuggling via Base64, few-shot poisoning, defined dictionary attacks, virtualization (grandma trick), DAN jailbreak personas, indirect injection through fetched content, and markdown-image data exfiltration. Each uses a harmless 'I am a sandwich' test string to demonstrate success.","whyItMatters":"Defenders benefit from a clear taxonomy of common prompt injection and jailbreak patterns, especially the agent-targeting indirect injection and markdown-image exfiltration vectors.","threatTypeTags":["prompt-injection","jailbreak","data-exfiltration","indirect-prompt-injection"],"affectedTechTags":["llm","ai-agents"],"threatActor":null,"relevanceScore":0.95,"severityScore":0.4,"sources":[{"sourceId":"hn-search","title":"A Catalog of Prompt Injection Techniques | Blog | Archestra","link":"https://archestra.ai/blog/10-basic-prompt-injections"}],"sourceItemIds":["28e15dc9c685df6a7f84d1e56d43a186bbcb2ecb"],"publishedAt":"2026-06-15T14:00:58.000Z","firstReportedAt":"2026-06-15T14:00:58.000Z","curatedAt":"2026-06-27T04:32:09.204Z","itemType":"research","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[]},"score":0.26021993038416924},{"item":{"id":"96a55fdb3e609d015a733c2f42b782d9be4b33c2","incidentId":"7ef5b19d9c4494e8d8af47e5080ddafbd72a7e6c","title":"Prompt Injection Is Just SSRF for Text | MCP Security → Part 3 | by Abhishek meena | Jul, 2026 | Medium","summary":"Part 3 of an MCP bug bounty guide by Abhishek meena frames MCP prompt injection as analogous to SSRF: tool outputs (URLs, files, emails, API responses) are attacker-controlled text that the model reads and treats as instructions. The write-up explains how to find, exploit, and argue indirect prompt injection via tool output, with sanitized PoCs referenced.","whyItMatters":"MCP tool output is an under-audited attack surface, and framing indirect prompt injection as 'SSRF for text' gives defenders and bug hunters a concrete mental model to identify where agent tools ingest attacker-controlled content.","threatTypeTags":["prompt-injection","tool-abuse","data-exfiltration"],"affectedTechTags":["mcp","llm","ai-agents"],"threatActor":null,"relevanceScore":0.9,"severityScore":0.55,"sources":[{"sourceId":"firecrawl-search","title":"Prompt Injection Is Just SSRF for Text | MCP Security → Part 3 | by Abhishek meena | Jul, 2026 | Medium","link":"https://medium.com/@Aacle/prompt-injection-is-just-ssrf-for-text-7c864c73571e"}],"sourceItemIds":["295a8c289931a10c4f66f038392f70ce74334d65"],"publishedAt":"2026-07-20T05:00:00.012Z","firstReportedAt":"2026-07-20T05:00:00.012Z","curatedAt":"2026-07-20T05:37:47.005Z","itemType":"analysis","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://medium.com/@Aacle/prompt-injection-is-just-ssrf-for-text-7c864c73571e","domain":"medium.com","slug":"medium","tier":"known","title":"Prompt Injection Is Just SSRF for Text | MCP Security → Part 3 | by Abhishek meena | Jul, 2026 | Medium","pageTitle":"Prompt Injection Is Just SSRF for Text | MCP Security → Part 3 | by Abhishek meena | Jul, 2026 | Medium"}]},"score":0.2560860507385688},{"item":{"id":"f02fe92ddd255aebcd196349dfce81024b26336d","incidentId":"e53eb8851ef7cd5edf925188e32ffcfe54223992","title":"Prompt Injection: Are Invisible Instructions the Next AI Risk in Disputes? – Daily Jus by Jus Mundi","summary":"Legal analysts at Greenberg Traurig examine prompt injection as an emerging AI risk in legal disputes, describing how hidden instructions embedded in documents can manipulate AI tools that ingest them into producing skewed or incomplete outputs. The piece contrasts this with AI hallucinations and notes a court has already dealt with the issue.","whyItMatters":"Prompt injection via weaponized documents poses a concrete risk in high-stakes legal and dispute contexts where AI tools ingest adversarial files, making defenders aware of indirect prompt injection beyond the technical domain.","threatTypeTags":["prompt-injection","indirect-prompt-injection","data-poisoning"],"affectedTechTags":["llm","generative-ai"],"threatActor":null,"relevanceScore":0.6,"severityScore":0.3,"sources":[{"sourceId":"firecrawl-search","title":"Prompt Injection: Are Invisible Instructions the Next AI Risk in Disputes? – Daily Jus by Jus Mundi","link":"https://dailyjus.com/legal-tech/2026/07/prompt-injection-are-invisible-instructions-the-next-ai-risk-in-disputes"}],"sourceItemIds":["60a1d3be84a31d49b439e54e75a732459956678b"],"publishedAt":"2026-07-18T04:45:00.006Z","firstReportedAt":"2026-07-18T04:45:00.006Z","curatedAt":"2026-07-18T05:06:31.369Z","itemType":"analysis","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://dailyjus.com/legal-tech/2026/07/prompt-injection-are-invisible-instructions-the-next-ai-risk-in-disputes","domain":"dailyjus.com","slug":null,"tier":"unknown","title":"Prompt Injection: Are Invisible Instructions the Next AI Risk in Disputes? – Daily Jus by Jus Mundi","pageTitle":"Prompt Injection: Are Invisible Instructions the Next AI Risk in Disputes? – Daily Jus by Jus Mundi"}]},"score":0.25533619459436185}]}