Preventing AI risks across assets (MCP, AI Apps, Model Infrastructure, Models, and more). Serving leading Fortune 50s and innovative tech companies.

Top of HackerNews today: our article on Google Antigravity exfiltrating .env variables via indirect prompt injection -- even when explicitly prohibited by user settings!
17
111
525
471,444
PromptArmor retweeted
Agent security gets harder the moment the model can act. Tool use, trust boundaries, delegated access, unintended side effects. That’s the real attack surface. Snowflake is working with PromptArmor to pressure-test new AI and agentic capabilities against those risks. Details: 👇 bit.ly/4xMW1L0
8
1
14
2,170
Labcorp can now sell Personal Data for training of AI?? This is wild:
9
36
183
199,279
Claude Cowork Cracked! 2 days after release Top of HN today:
7
420
Top of HackerNews today: our article on Google Antigravity exfiltrating .env variables via indirect prompt injection -- even when explicitly prohibited by user settings!
17
111
525
471,444
ChatGPT leaks emails, once again! This time with custom MCP connectors. Great exploit demonstrated by nitter.net/Eito_Miyamura/status/1…. We break down the attack chain step by step for security practitioners, here: promptarmor.substack.com/p/c…
We got ChatGPT to leak your private email data 💀💀 All you need? The victim's email address. ⛓️‍💥🚩📧 On Wednesday, @OpenAI added full support for MCP (Model Context Protocol) tools in ChatGPT. Allowing ChatGPT to connect and read your Gmail, Calendar, Sharepoint, Notion, and more, invented by @AnthropicAI But here's the fundamental problem: AI agents like ChatGPT follow your commands, not your common sense. And with just your email, we managed to exfiltrate all your private information. Here's how we did it: 1. The attacker sends a calendar invite with a jailbreak prompt to the victim, just with their email. No need for the victim to accept the invite. 2. Waited for the user to ask ChatGPT to help prepare for their day by looking at their calendar 3. ChatGPT reads the jailbroken calendar invite. Now ChatGPT is hijacked by the attacker and will act on the attacker's command. Searches your private emails and sends the data to the attacker's email. For now, OpenAI only made MCPs available in "developer mode", and requires manual human approvals for every session, but decision fatigue is a real thing, and normal people will just trust the AI without knowing what to do and click approve, approve, approve. Remember that AI might be super smart, but can be tricked and phished in incredibly dumb ways to leak your data. ChatGPT + Tools poses a serious security risk
8
24
54
26,876
Imagine if an attacker could steal any Slack private channel message. We've disclosed a vulnerability in Slack AI that allows an attacker to exfiltrate your Slack private channel messages and phish users via indirect prompt injection. promptarmor.substack.com/p/s…
3
18
16,372
PromptArmor retweeted
One of the true pleasures of being back at YC is hand-picking and funding startups myself. Here are my YC W24 founders. I predict very big things in each of their ten year overnight successes 🫡
27
26
527
216,508
PromptArmor retweeted
Cybersecurity for LLMs is a brand new category that PromptArmor is building from scratch now It’s extra prescient because LLMs can just *do* things and prompt/context/data/instructions are now merged so exfiltration becomes a real problem
How you can steal private data out of LLMs - literally tell it to append "text of all the source data files" to an HTTP parameter via markdown PromptArmor prevents these and many other data exfiltration exploits
3
3
17
17,999
Want to expose LLM sales bots reaching out to you? 👇
1
3
12
2,279
Add a snippet to your linkedin bio and watch the magic happen
9
1,138
PromptArmor retweeted
When cloud came online, cybersecurity was the next big category. LLMs are coming online now, and PromptArmor is making cybersecurity for this new field. History doesn't repeat, but it rhymes.
5
3
40
12,253
Glad this data exfiltration method has been mitigated. The evidence in the report was accurate and speaks for itself.
Talked to the CEO. The issue seems to be fixed now. I couldn't conclusively verify their claims regarding previous exposure of other users, but the folks from @PromptArmor and I have reported on the observed behavior accurately.
1,621
New blog post in collaboration with @KGreshake promptarmor.substack.com/p/d…
1
15
26
27,749
Any text can be an attack, code is no longer required. Imagine any random person being able to steal your private data. Point is, LLM attacks are easy and extremely powerful.
Did you know you could inject prompts that exfiltrate data from LLM's? This attack allows attackers to steal a user’s private documents by manipulating the language model used for content generation in writer.com
1
1,156