Policy
prompt injection attacks
Prompt injection attacks are a type of security vulnerability where malicious actors manipulate an AI's instructions by crafting deceptive inputs, causing the AI to perform unintended actions or reveal sensitive information.
Why it’s in the news: They are in the news because major AI companies like OpenAI are implementing new features, such as Lockdown Mode, to specifically counter these attacks and protect user data.
Latest on prompt injection attacks
- Prompt Injection Attacks Are Thwarting AI Hacking Agents
- Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments
- OpenAI adds Lockdown Mode to ChatGPT to block data theft from prompt injection attacks
- Why OpenAI is disabling ChatGPT web access to fight prompt injection attacks
- OpenAI unveils Lockdown Mode to protect sensitive data from prompt injection attacks
- Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google
- Researchers discovered two campaigns that embedded indirect prompt injections in malicious websites to manipulate autonomous AI agents into making cryptocurrency payments.
- The attack tricks employees into clicking specially crafted links designed to leak sensitive corporate data.
- Most enterprises deploying web agents today haven't mapped what happens when an attacker embeds a prompt injection into a customer email, a vendor contract, or a support ticket — and the agent executes it anyway
- AI web agents powered by GPT-5 and Gemini lack reliable defenses against prompt injection attacks
- StakeBench, a stakeholder-centric benchmark developed by the team, tested multiple attack scenarios
- OpenAI rolls out Lockdown Mode for users handling sensitive information
Connections
12 entities linked to prompt injection attacks across the news graph.
Under pressure from (7)
Also connected to (5)