> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> 'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets

[SOURCE] BleepingComputer [AUTHOR: Ax Sharma] [DATE: 11/07/2026 09:03] [LANGUAGE: EN]
A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repo's .env and write every secret into the code as a list of numbers. [...]
[messages.read_original_source] →