
Embrace The Red
296 posts

Embrace The Red
@EmbraceTheRed23
learn the hacks, stop the attacks.



The Hugging Face AI intrusion hasn't gotten much attention so far, yet it's a "milestone" from multiple perspectives youtu.be/JQQYhNK6AyU



Ahoy! 🏴☠️ Claude got network access. When enabled, it can also communicate with Anthropic APIs! Twist: Attacker sets their own API key in prompt injection payload to upload user's data to their account 🔥



🔥 Took the Month of AI Bugs wreckage and turned it into a paper - AI Kill Chain 🧨 - Test cases and exploit chains (data exfil, rce, zombies!) - AgentHopper (a working AI virus for coding agents) 🦠 - SpAIware - Normalization of Deviance in AI zenodo.org/records/187692…






Follow him: @wunderwuzzi23 Helpful resources 👇🏻 The Month of AI Bugs 2025 Source: embracethered.com/blog/posts/202… Exfiltrating Your ChatGPT Chat History and Memories With Prompt Injection Source: embracethered.com/blog/posts/202… Turning ChatGPT Codex Into A ZombAI Agent Source: embracethered.com/blog/posts/202… Anthropic Filesystem MCP Server: Directory Access Bypass via Improper Path Validation Source: embracethered.com/blog/posts/202… Cursor IDE: Arbitrary Data Exfiltration Via Mermaid (CVE-2025-54132) Source: embracethered.com/blog/posts/202… Amp Code: Arbitrary Command Execution via Prompt Injection Fixed Source: embracethered.com/blog/posts/202… I Spent $500 To Test Devin AI For Prompt Injection So That You Don't Have To Source: embracethered.com/blog/posts/202… How Devin AI Can Leak Your Secrets via Multiple Means Source: embracethered.com/blog/posts/202… AI Kill Chain in Action: Devin AI Exposes Ports to the Internet with Prompt Injection Source: embracethered.com/blog/posts/202… ZombAI Exploit with OpenHands: Prompt Injection To Remote Code Execution Source: embracethered.com/blog/posts/202… OpenHands and the Lethal Trifecta: How Prompt Injection Can Leak Access Tokens Source: embracethered.com/blog/posts/202… Claude Code: Data Exfiltration with DNS (CVE-2025-55284) Source: embracethered.com/blog/posts/202… GitHub Copilot: Remote Code Execution via Prompt Injection Source: embracethered.com/blog/posts/202… Google Jules: Vulnerable to Data Exfiltration Issues Source: embracethered.com/blog/posts/202… Google Jules: Remote Code Execution ZombAI Source: embracethered.com/blog/posts/202… Google Jules: Invisible Prompt Injection Source: embracethered.com/blog/posts/202… Amp Code Fixed: Invisible Prompt Injection Source: embracethered.com/blog/posts/202… Amp Code Fixed: Data Exfiltration via Images Source: embracethered.com/blog/posts/202… Amazon Q Developer: Data Exfil via DNS Source: embracethered.com/blog/posts/202… Amazon Q Developer: Remote Code Execution Source: embracethered.com/blog/posts/202… Amazon Q Developer Interprets Hidden Instructions Source: embracethered.com/blog/posts/202… Windsurf: Data Exfiltration Vulnerabilities Source: embracethered.com/blog/posts/202… Windsurf: SPAIware Exploit - Persistent Prompt Injection Source: embracethered.com/blog/posts/202… Windsurf: Sneaking Invisible Instructions for Prompt Injection Source: embracethered.com/blog/posts/202… ChatGPT Deep Research Connectors: Data Spill and Leaks Source: embracethered.com/blog/posts/202… Manus AI Kill Chain: Expose Port - VS Code Server on Internet Source: embracethered.com/blog/posts/202… AWS Kiro: Arbitrary Command Execution with Indirect Prompt Injection Source: embracethered.com/blog/posts/202… Cline: Vulnerable to Data Exfiltration Source: embracethered.com/blog/posts/202… Windsurf: Dangers - Lack of Security Controls for MCP Server Tool Invocation Source: embracethered.com/blog/posts/202… AgentHopper: A PoC AI Virus Source: embracethered.com/blog/posts/202… Wrapping Up Month of AI Bugs Source: embracethered.com/blog/posts/202…





