Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Nscale buys Anyscale as it seeks to own more of the AI compute stack

    July 31, 2026

    Daisy One Review: Comfy and Tactile Headphones

    July 31, 2026

    How the 60 Minutes Editorial Process Is Supposed to Work

    July 31, 2026
    Facebook Twitter Instagram
    • Tech
    • Gadgets
    • Spotlight
    • Gaming
    Facebook Twitter Instagram
    iGadgets TechiGadgets Tech
    Subscribe
    • Home
    • Gadgets
    • Insights
    • Apps

      Nscale buys Anyscale as it seeks to own more of the AI compute stack

      July 31, 2026

      Netflix lands global streaming deal for ‘The Walking Dead’

      July 31, 2026

      Meta says AI is making it easier to build new apps — and more are coming

      July 31, 2026

      When will fusion power startup Commonwealth Fusion Systems go public?

      July 31, 2026

      Spotify launches ‘User Notes’ to let users add memories to songs

      July 31, 2026
    • Gear
    • Mobiles
      1. Tech
      2. Gadgets
      3. Insights
      4. View All

      Daisy One Review: Comfy and Tactile Headphones

      July 31, 2026

      The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key

      July 31, 2026

      The World Is Too Hot. El Niño Is Partly to Blame

      July 31, 2026

      SelectBlinds Promo Codes & Coupons: Save on Custom Window Treatments

      July 31, 2026

      March Update May Have Weakened The Haptics For Pixel 6 Users

      April 2, 2022

      Project 'Diamond' Is The Galaxy S23, Not A Rollable Smartphone

      April 2, 2022

      The At A Glance Widget Is More Useful After March Update

      April 2, 2022

      Pre-Order The OnePlus 10 Pro For Just $1 In The US

      April 2, 2022

      Motorola Edge+ Review: It Checks A Lot Of Boxes

      April 2, 2022

      This Smartphone Concept Design Is Different… In A Good Way

      April 2, 2022

      Twitter Just Made Searching Your Direct Messages Better

      April 2, 2022

      That Netflix Price Hike Is Starting To Take Place

      April 2, 2022

      Latest Huawei Mobiles P50 and P50 Pro Feature Kirin Chips

      January 15, 2021

      Samsung Galaxy M62 Benchmarked with Galaxy Note10’s Chipset

      January 15, 2021
      9.1

      Review: T-Mobile Winning 5G Race Around the World

      January 15, 2021
      8.9

      Samsung Galaxy S21 Ultra Review: the New King of Android Phones

      January 15, 2021
    • Computing
    iGadgets TechiGadgets Tech
    Home»Tech»Prompt Injection Attacks Are Thwarting AI Hacking Agents
    Tech

    Prompt Injection Attacks Are Thwarting AI Hacking Agents

    adminBy adminJuly 18, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Prompt Injection Attacks Are Thwarting AI Hacking Agents
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Prompt injections, the malicious commands attackers embed into content to entice large language models to follow them, have been attackers’ go-to tool for turning AI platforms against their users. A well-phrased command sneaked into an email or calendar invitation is often all it takes to cause the LLM to exfiltrate sensitive data or follow other harmful actions.

    Now, defenders are embracing the prompt injection, too.

    Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents. The prompts direct the attacking LLM to perform an action forbidden by its guardrails, the safety barriers AI developers erect to prevent it from taking harmful actions. The LLM responds by shutting down.

    Examples are a prompt that orders the LLM to provide steps for developing inhalable Anthrax spores, or, in the case of LLMs from Chinese developers, make references to the iconic Tank Man from the 1989 Tiananmen Square massacre. Once the LLM encounters these forbidden commands, it no longer follows its existing commands. The researchers have named the technique context bombing.

    “Ultimately we’re triggering a refusal mechanism in the context,” said Andy Smith, cofounder and CEO of Tracebit, when explaining the name choice. “What we’re trying to capture is the fact that this does have a strong, sharp effect and one that can be difficult for the agents to come back from. Once they get that into their context they are going to keep refusing.”

    Tracebit says initial testing suggests context bombing has great potential. They tested Opus 4.8, Gemini 3.1 Pro, GLM 5.2, DeepSeek 4 Pro, and Kimi 2.6 by giving them instructions to perform routine developer tasks that led the models to enumerate resources and stumble onto the planted strings. They ran the models inside a simulated AWS environment.

    “Across five leading models and 152 attack runs, planting one of these strings in a decoy secret cut the rate at which agents seized full account admin from 57 percent to 5 percent, and complete compromise (where they also left themselves a persistent foothold) from 36 percent to 1 percent,” Monday’s post reported. “The most capable agent in our tests, Opus 4.8, went from achieving admin access in 93 percent of runs to failing every single time when confronted with a context bomb.”

    Averaged across the five models and the 152 runs, the results included:

    • Admin privilege escalation fell from 57 percent to 5 percent
    • Admin escalation with a persistent foothold fell from 36 percent to 1 percent
    • Runs achieving any attack path fell from 91 percent to 15 percent
    • On average, a run went from completing 1.53 paths successfully to just 0.16
    • No runs were able to complete an attack path without at least triggering a canary detection

    The research builds on findings from May, when Tracebit introduced a method for defenders to receive warnings when their infrastructure is under attack from AI agentic adversaries. It comes in the form of AWS resources that look like ones serving a legitimate purpose but, in fact, aren’t used at all. They sit alongside the resources that are used. When they are probed by agentic AI, defenders receive an alert. Like “canaries” taken into coal mines, these resources allow defenders to detect a threat before it has fatal consequences.

    Security,Security / Cyberattacks and Hacks,Poison Pillsars technica,artificial intelligence,cybersecurity,hacking,security,vulnerabilities,machine learning#Prompt #Injection #Attacks #Thwarting #Hacking #Agents1784388857

    Agents ars technica artificial intelligence Attacks cybersecurity hacking injection machine learning Prompt Security Thwarting vulnerabilities
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website
    • Tumblr

    Related Posts

    Daisy One Review: Comfy and Tactile Headphones

    July 31, 2026

    The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key

    July 31, 2026

    The World Is Too Hot. El Niño Is Partly to Blame

    July 31, 2026
    Add A Comment

    Leave A Reply Cancel Reply

    Editors Picks
    8.5

    Apple Planning Big Mac Redesign and Half-Sized Old Mac

    January 5, 2021

    Autonomous Driving Startup Attracts Chinese Investor

    January 5, 2021

    Onboard Cameras Allow Disabled Quadcopters to Fly

    January 5, 2021
    Top Reviews
    9.1

    Review: T-Mobile Winning 5G Race Around the World

    By admin
    8.9

    Samsung Galaxy S21 Ultra Review: the New King of Android Phones

    By admin
    8.9

    Xiaomi Mi 10: New Variant with Snapdragon 870 Review

    By admin
    Advertisement
    Demo
    iGadgets Tech
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Tech
    • Gadgets
    • Mobiles
    • Our Authors
    © 2026 ThemeSphere. Designed by WPfastworld.
    "korean kbj​ "korean bj "koreanbj​

    Type above and press Enter to search. Press Esc to cancel.