llmsecurity (2)

31187949466?profile=RESIZE_400xOur friends at SentinelLABS have analyzed a Rust macOS implant that embeds a 3.5 KB prompt-injection payload containing 38 fabricated “system” messages, designed to steer an LLM-assisted triage pipeline into aborting or refusing analysis.  Command-and-control runs over a Telegram Bot API polling loop, with AES-GCM payloads over certificate-pinned TLS.

The implant self-redacts its Telegram bot token in its own runtime output, denying it to anyone who captures logs or crash artifacts.  Analysts ha

13733277071?profile=RESIZE_400xCybersecurity firm Tenable discovered three critical flaws that allowed for prompt injection and data exfiltration from Google’s Gemini AI.  Learn why AI assistants are the new weak link.  Researchers have recently discovered three critical security flaws within Google’s Gemini AI assistant suite,[1] which they’ve dubbed the “Gemini Trifecta.”  These vulnerabilities, publicly disclosed around October 1, 2025, made Gemini vulnerable to prompt injection and data exfiltration, putting users at risk