Embrace The Red

296 posts

Embrace The Red banner
Embrace The Red

Embrace The Red

@EmbraceTheRed23

learn the hacks, stop the attacks.

Katılım Ocak 2023
0 Takip Edilen149 Takipçiler
Embrace The Red retweetledi
Johann Rehberger
Johann Rehberger@wunderwuzzi23·
Talks from Stanford's Real-World AI Security Conference are now on YouTube! Full list is here seclab.stanford.edu/RealWorldAIsec/ So many amazing talks, I really liked: 🔹 AI Agents Enable Adaptive Computer Worms, Nicolas Papernot 🔥 🔹 The Road to Hell Is Paved with Helpful Agents, Vitaly Shmatikov 🤯 🔹 Evaluating and Defending Against Prompt Injection Attacks, Edoardo Debenedetti 🐪💥 ...and many more excellent talks covering outstanding research!
English
4
17
62
5K
Embrace The Red retweetledi
Johann Rehberger
Johann Rehberger@wunderwuzzi23·
Anthropic: "Risk we missed" Happy to share that Claude Pirate got a subtle mention in the latest Anthropic engineering blog post, also shares how they fixed it 🙌
Johann Rehberger tweet media
Johann Rehberger@wunderwuzzi23

Ahoy! 🏴‍☠️ Claude got network access. When enabled, it can also communicate with Anthropic APIs! Twist: Attacker sets their own API key in prompt injection payload to upload user's data to their account 🔥

English
2
8
48
10.6K
Embrace The Red retweetledi
Garry Tan
Garry Tan@garrytan·
Attackers can exfiltrate user files from Cowork by exploiting an unremediated vulnerability in Claude’s coding environment, which now extends to Cowork. The vulnerability was first identified in Claude.ai chat before Cowork existed by Johann Rehberger, who disclosed the vulnerability. It was acknowledged but not remediated by Anthropic. promptarmor.com/resources/clau…
English
57
44
528
120.4K
Embrace The Red retweetledi
Johann Rehberger
Johann Rehberger@wunderwuzzi23·
Fixed. 🙌 Stop by DEF CON Singapore to learn more about what happened here with M365 Copilot, and a lot of other shenanigans. 😈 msrc.microsoft.com/update-guide/v… Shout out to Microsoft for addressing this promptly.
Johann Rehberger tweet media
English
1
1
26
2.1K
Embrace The Red retweetledi
8en N@$$!
8en N@$$!@ben_nassi·
🚨 Registration is now open! 🚨 We are excited to announce that registration is officially open for the Real World AI Security Conference 2026. 📅 June 23–25, 2026 📍 Arrillaga Alumni Center, Stanford University If you work on AI security, adversarial ML, LLM safety, AI system attacks, or defenses, this event is designed for you. 👉 Register here (we have a limitation on the number of attendees): seclab.stanford.edu/RealWorldAIsec/ We look forward to bringing together the community to explore the latest advances in AI security in the real world. #AISecurity #CyberSecurity #MachineLearningSecurity #LLMSecurity #AdversarialML #AIResearch #AIConference #SecurityResearch #RealWorldAISecurity
English
2
8
73
9.4K
Embrace The Red retweetledi
Johann Rehberger
Johann Rehberger@wunderwuzzi23·
NanoClaw 🔥 Don't give AI access to sensitive stuff you care about. Trust No AI, as usual.
Johann Rehberger tweet media
English
6
3
33
6.1K
Embrace The Red
Embrace The Red@EmbraceTheRed23·
Month of AI Bugs still going strong! 🚀 Learn the hacks, stop the attacks.
7h3h4ckv157@7h3h4ckv157

Follow him: @wunderwuzzi23 Helpful resources 👇🏻 The Month of AI Bugs 2025 Source: embracethered.com/blog/posts/202… Exfiltrating Your ChatGPT Chat History and Memories With Prompt Injection Source: embracethered.com/blog/posts/202… Turning ChatGPT Codex Into A ZombAI Agent Source: embracethered.com/blog/posts/202… Anthropic Filesystem MCP Server: Directory Access Bypass via Improper Path Validation Source: embracethered.com/blog/posts/202… Cursor IDE: Arbitrary Data Exfiltration Via Mermaid (CVE-2025-54132) Source: embracethered.com/blog/posts/202… Amp Code: Arbitrary Command Execution via Prompt Injection Fixed Source: embracethered.com/blog/posts/202… I Spent $500 To Test Devin AI For Prompt Injection So That You Don't Have To Source: embracethered.com/blog/posts/202… How Devin AI Can Leak Your Secrets via Multiple Means Source: embracethered.com/blog/posts/202… AI Kill Chain in Action: Devin AI Exposes Ports to the Internet with Prompt Injection Source: embracethered.com/blog/posts/202… ZombAI Exploit with OpenHands: Prompt Injection To Remote Code Execution Source: embracethered.com/blog/posts/202… OpenHands and the Lethal Trifecta: How Prompt Injection Can Leak Access Tokens Source: embracethered.com/blog/posts/202… Claude Code: Data Exfiltration with DNS (CVE-2025-55284) Source: embracethered.com/blog/posts/202… GitHub Copilot: Remote Code Execution via Prompt Injection Source: embracethered.com/blog/posts/202… Google Jules: Vulnerable to Data Exfiltration Issues Source: embracethered.com/blog/posts/202… Google Jules: Remote Code Execution ZombAI Source: embracethered.com/blog/posts/202… Google Jules: Invisible Prompt Injection Source: embracethered.com/blog/posts/202… Amp Code Fixed: Invisible Prompt Injection Source: embracethered.com/blog/posts/202… Amp Code Fixed: Data Exfiltration via Images Source: embracethered.com/blog/posts/202… Amazon Q Developer: Data Exfil via DNS Source: embracethered.com/blog/posts/202… Amazon Q Developer: Remote Code Execution Source: embracethered.com/blog/posts/202… Amazon Q Developer Interprets Hidden Instructions Source: embracethered.com/blog/posts/202… Windsurf: Data Exfiltration Vulnerabilities Source: embracethered.com/blog/posts/202… Windsurf: SPAIware Exploit - Persistent Prompt Injection Source: embracethered.com/blog/posts/202… Windsurf: Sneaking Invisible Instructions for Prompt Injection Source: embracethered.com/blog/posts/202… ChatGPT Deep Research Connectors: Data Spill and Leaks Source: embracethered.com/blog/posts/202… Manus AI Kill Chain: Expose Port - VS Code Server on Internet Source: embracethered.com/blog/posts/202… AWS Kiro: Arbitrary Command Execution with Indirect Prompt Injection Source: embracethered.com/blog/posts/202… Cline: Vulnerable to Data Exfiltration Source: embracethered.com/blog/posts/202… Windsurf: Dangers - Lack of Security Controls for MCP Server Tool Invocation Source: embracethered.com/blog/posts/202… AgentHopper: A PoC AI Virus Source: embracethered.com/blog/posts/202… Wrapping Up Month of AI Bugs Source: embracethered.com/blog/posts/202…

English
0
0
0
46
Embrace The Red retweetledi
Johann Rehberger
Johann Rehberger@wunderwuzzi23·
given enough agents, all bugs are shallow
English
2
3
10
3.7K
Embrace The Red retweetledi
Johann Rehberger
Johann Rehberger@wunderwuzzi23·
As personal AI agents increasingly send messages to chat apps, it’s worth revisiting link unfurling. 😈 It's a straightforward data exfiltration vector. Attacker hijacks your AI to embed private data in URL, posts it & chatapp auto connects. 0-click.🔥 embracethered.com/blog/posts/202…
English
2
2
15
816
Embrace The Red retweetledi
8en N@$$!
8en N@$$!@ben_nassi·
🚀 𝗧𝗵𝗲 𝗥𝗲𝗮𝗹 𝗪𝗼𝗿𝗹𝗱 𝗔𝗜 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗖𝗼𝗻𝗳𝗲𝗿𝗲𝗻𝗰𝗲 𝟮𝟬𝟮𝟲 🚀 We are excited to announce the first 3 day 𝗥𝗲𝗮𝗹 𝗪𝗼𝗿𝗹𝗱 𝗔𝗜 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗖𝗼𝗻𝗳𝗲𝗿𝗲𝗻𝗰𝗲, taking place on 𝗝𝘂𝗻𝗲 𝟮𝟯–𝟮𝟱, 𝟮𝟬𝟮𝟲, at 𝗦𝘁𝗮𝗻𝗳𝗼𝗿𝗱 𝗨𝗻𝗶𝘃𝗲𝗿𝘀𝗶𝘁𝘆. The conference is intended to brief the most impactful AI security work presented over the past year at 𝗹𝗲𝗮𝗱𝗶𝗻𝗴 𝗶𝗻𝗱𝘂𝘀𝘁𝗿𝘆 𝗰𝗼𝗻𝗳𝗲𝗿𝗲𝗻𝗰𝗲𝘀 (Black Hat, DEF CON, RSAC, CCC) and 𝘁𝗼𝗽 𝗮𝗰𝗮𝗱𝗲𝗺𝗶𝗰 𝘃𝗲𝗻𝘂𝗲𝘀 (CCS, IEEE S&P, USENIX Security, NDSS). 𝗧𝗵𝗶𝘀 𝗶𝘀 𝗮 𝗻𝗼𝗻-𝗽𝗿𝗼𝗳𝗶𝘁, 𝗰𝗼𝗺𝗺𝘂𝗻𝗶𝘁𝘆-𝗱𝗿𝗶𝘃𝗲𝗻 𝗰𝗼𝗻𝗳𝗲𝗿𝗲𝗻𝗰𝗲 focused exclusively on technical AI security talks with real-world impact on deployed AI systems. The goal is to curate a concise agenda that distills the most important advances in AI security from the past year, while bringing together 𝗶𝗻𝗱𝘂𝘀𝘁𝗿𝘆 𝗽𝗿𝗮𝗰𝘁𝗶𝘁𝗶𝗼𝗻𝗲𝗿𝘀 𝗮𝗻𝗱 𝗮𝗰𝗮𝗱𝗲𝗺𝗶𝗰 𝗿𝗲𝘀𝗲𝗮𝗿𝗰𝗵𝗲𝗿𝘀 to establish new connections, collaborations, and future research directions. We will share additional details soon. Here is the link to the website of the conference: seclab.stanford.edu/RealWorldAIsec/ #security #ai #llm #ai_security #cybersecurity #infosec
8en N@$$! tweet media
English
1
12
29
2.2K
Embrace The Red retweetledi
Johann Rehberger
Johann Rehberger@wunderwuzzi23·
39c3!!! 🚀🚀🚀
Johann Rehberger tweet media
3
1
32
1.7K