← heapsort-ai

prompt injection

26 items

ARTICLEDEV.to AI·4/16/2026

NEW PROMPT INJECTION

This article by Karen Tonoyan introduces the concept of Narrative Drift Injection (NDI) as a new dimension of prompt injection. Unlike classic attacks, NDI manipulates the AI model by drawing it into a narrative it co-creates, causing it to lose vigilance at the session level.

31
RESEARCHDEV.to AI·5d ago

Indirect Prompt Injection via Notifications Hijacks Google Gemini on Android

A SafeBreach researcher demonstrated an indirect prompt injection vulnerability in Google Gemini on Android, allowing the assistant to execute real device actions without user awareness via notifications. While Google has patched the issue, the research exposes a large attack surface where any app capable of pushing a notification becomes a potential injection vector.

28
ARTICLEDEV.to AI·5d ago

Notification Hijacking: How WhatsApp and Slack Content Could Weaponize Google Gemini

Researchers uncovered a prompt injection vulnerability in Google Gemini on Android, where content from app notifications like WhatsApp and Slack could be misinterpreted as malicious instructions. This flaw allows an attacker to potentially control Gemini to open browsers, send messages, or poison its long-term memory, all without requiring a malicious app or special permissions.

28
ARTICLEDEV.to AI·5/5/2026

Your AI Assistant is Gullible: Building a "Semantic Airgap" for Gmail Connectors

The content describes "Indirect Prompt Injection" as a vulnerability where AI assistants with Gmail access can be tricked by malicious emails into performing unwanted actions. It proposes a "Semantic Airgap" solution, using a "Dumb Sanitizer" to strip imperative power from external data before it reaches the "High-Intelligence" agent, preventing such attacks.

27
ARTICLEDEV.to AI·5/1/2026

We Audited 7 Official MCP Servers — 6 Got F

An audit of Anthropic's Model Context Protocol (MCP) servers found that 6 out of 7 had alarmingly bad prompt-level defenses, making them vulnerable to prompt injection. This issue stems from the trust contract between AI agents and tool descriptions, similar to recent "Comment & Control" disclosures.

27
ARTICLEDEV.to AI·4/15/2026

Enterprise AI Security in 2026: A Practical Guide for Modern Organizations

This article discusses how the rapid adoption of artificial intelligence in enterprises necessitates a rethinking of security, as AI systems introduce new attack surfaces not covered by traditional cybersecurity. It addresses challenges such as sensitive data exposure, prompt injection attacks, and model manipulation, emphasizing the need to protect models, data, and decisions in an AI-driven environment.

27