Posts

Prompt Injection Attacks Explained With Real Examples and Defences

This article provides an in-depth explanation of prompt injection attacks against LLM-based systems, covering both direct and indirect attack types. It uses real-world examples, such as the EchoLeak vulnerability (CVE-2025-32711), which achieved zero-click data exfiltration through Microsoft 365 Copilot, to demonstrate how hidden instructions embedded in emails, documents, or web pages can override an AI assistant's intended behavior. The article explains why prompt injection is fundamentally difficult to fix, noting that models cannot reliably distinguish between trusted system instructions and untrusted content once they are concatenated in the same context window. Defence recommendations include architectural separation of instructions from data using structural delimiters, input sanitization, output scanning, and restricting agent capabilities to limit the blast radius of a successful injection.  https://clearpathsecurity.co.uk/prompt-injection-attacks-explained-with-real-examp...

WSO2 CVSS 10 API Flaw Exploited 12 Days Before KEV: Active Exploitation of CVE-2026-5430

This article reports on the critical JWT authentication bypass vulnerability CVE-2026-5430 affecting WSO2 API Manager (versions 4.1.0–4.6.0), API Control Plane, Traffic Manager, and Universal Gateway. The flaw carries a CVSS score of 10.0 in multi-tenant deployments (9.8 in single-tenant) and stems from improper JWT signature verification that allows attackers to forge tokens signed with unsupported algorithms and gain full administrative access. Although patches were available since April 2026, active exploitation was detected by watchTowr's honeypot network starting September 13, 2026, with CISA adding the vulnerability to its KEV catalog on September 24, 2026, mandating federal remediation by September 27. The article details the exploitation timeline, affected products, and defense recommendations including immediate patching and restricting access to management interfaces .  https://tech-insider.org/wso2-cvss-10-api-flaw-exploited-kev-2026/

Active Exploitation Alert: WSO2 API Manager / Gateway JWT Authentication Bypass — CVE-2026-5430 (WSO2-2026-5328) Added to CISA KEV

This security advisory warns of active exploitation of the critical vulnerability CVE-2026-5430 (WSO2-2026-5328), a JWT authentication bypass flaw caused by improper verification of cryptographic signature (CWE-347) in WSO2 API Manager, API Control Plane, Traffic Manager, and Universal Gateway products. CISA added the vulnerability to its KEV catalog on September 24, 2026, with in-the-wild exploitation confirmed since at least September 13, 2026. The flaw allows unauthenticated attackers to forge JWT tokens using unsupported algorithms to gain full administrative access. https://www.rescana.com/post/wso2-api-manager-cve-2026-5430-kev

How we found 24 Android vulnerabilities using our open-source AI security agent

O GitHub descreve como sua equipe de segurança utilizou um agente de segurança de IA de código aberto para identificar 24 vulnerabilidades no Android, detalhando a metodologia, as descobertas e a abordagem de análise automatizada de segurança.  https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/

Malicious npm Packages That Evade Defenses

In this short Schneier on Security post, Bruce Schneier flags a report on a sophisticated piece of malicious npm malware, calling it "impressive" and saying its sophistication suggests nation-state involvement — though he notes there is no direct evidence and certainly no attribution. The post itself is brief, linking out to the original analysis rather than detailing the technical methods, and the surrounding value comes from the comment thread. Commenters debate the finding (one argues it looks like the work of a merely competent expert rather than a nation-state), reiterate long-standing criticism of JavaScript's pervasiveness and security track record, and push back on install-time scanning alone — quoting the source article's advice that developers should not rely on install-time scanning and should also employ runtime behavioral analysis. Longtime commenter Clive Robinson points to his earlier "Castles-vs-Prisons" argument that malware cannot hide its ...

AI Is Changing Identity Attacks. Are Your Defenses Keeping Up?

The webinar examines how AI is increasing the sophistication of identity-based attacks through AI-powered phishing, deepfake impersonation, synthetic identities, and advanced social engineering. It argues that point-in-time identity verification may no longer be sufficient as attackers increasingly exploit trusted identities and bypass traditional controls. The discussion focuses on continuously evaluating identity risk throughout the identity lifecycle, identifying gaps in conventional identity security controls, and defining priorities for an updated identity security strategy.  https://www.govinfosecurity.com/webinars/ai-changing-identity-attacks-are-your-defenses-keeping-up-w-7384

NIST Standards Drive Demand for 11 Quantum Encryption Approaches

The article reports that organizations are accelerating evaluation of quantum-resistant encryption in 2026, driven by finalized NIST post-quantum standards and the threat of "Harvest Now, Decrypt Later" attacks, in which adversaries intercept and store encrypted data for future decryption once quantum computers running Shor's algorithm mature. It explains that current public-key cryptography rests on prime factorization and will not survive quantum processing, so post-quantum cryptography (PQC)—synonymous in practice with quantum-resistant encryption—instead relies on lattice-based math, hash structures, or physical laws, with schemes like Module Learning With Errors (M-LWE). NIST's first finalized PQC standards (FIPS 203 for ML-KEM key encapsulation, FIPS 204 for ML-DSA digital signatures, and FIPS 205 for stateless hash-based signatures) arrived in August 2024, and HQC was selected as a backup KEM in March 2025. The piece covers a tiered deployment landscape: softwa...