Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News 'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
BleepingComputer
Security 1 month ago

'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets

By Ax Sharma

A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repo's .env and write every secret into the code as a list of numbers. [...]

More from BleepingComputer

Leaving Threaticon

This link opens an external site that isn't part of the platform.