Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

https://www.securityweek.com/wp-content/uploads/2025/05/AI-attacks.jpeg

Researchers at Adversa AI discovered a new attack technique and named it Cryptographic Context Injection. They reported their findings to xAI on June 3, 2026, and attempted to coordinate disclosure on August 4 and August 10. At the time of writing, they had received no response.

They could not disclose to Google since jailbreaks are out of scope for its vulnerability disclosure program. Nevertheless, the success rate for the attack against Gemini had fallen by August.

The potential success of this attack by bad actors should be treated seriously. Adversa’s report includes prevention advice for defenders.

Cryptographic context injection

Safety guardrails classify prompt text without executing it. They cannot parse ciphertext into anything harmful and consequently allow its progress. The ciphertext, including an instruction and means for decryption, are run inside the model’s code execution sandbox. The result is the plaintext prompt is recovered inside the trusted execution context and...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/xADd7ydK8EewsHFJVVWYcG-1920-80.jpg

Germany has no problem with Tesla’s Full Self-Driving technology but urges a name change to avoid misleading customers — something Tesla should have done years ago

* Germany’s Federal Ministry of Transport is pushing for FSD approval * Regulators are concerned about the controversial name * The technology could be labelled “Tesla Assisted Driving” instead A recent statement from Germany’s Ministry of Transport reports that the country's Transport Minister, Steffen Bilger, is pushing to legalize