Mozilla Warns GitHub Repos Can Trick AI Tools Into Hacking Your PC

https://hothardware.com/contentimages/NewsItem/70988/content/16x9_2133x1200_highres-mozilla-0din-custom.jpg

Mozilla's 0din security team has discovered widespread prompt injection AI malware plaguing the GitHub ecosystem. This exploit, dubbed "indirect prompt injection," isn't the first of its kind. Previously, we've seen prompt injection malware impact the OpenAI ChatGPT Alias browser, and Microsoft has warned that the same could happen with Copilot.

In line with wider industry trends indicating Anthropic's Claude AI leads with developers, this exploit is only reported for Claude. However, the nature of the attack by no means limits it to Claude specifically, and outdated models will likely be even more vulnerable. It's a frightening prompt injection AI exploit as well, since it prompts the bot to download thinly-disguised malware from GitHub and proceed to fully compromise the user's system and GitHub credentials.

🚨 JAILBREAK ALERT 🚨

OPENAI: PWNED 😎
ATLAS-BROWSER: LIBERATED 🙌

WOW! There's a new AI browser on the block! Has some hefty guardrails in play, but...

Copyright of this story solely belongs to hothardware.com. To see the full text click HERE

Read more

https://assets.bwbx.io/images/users/iqjWHBFdfxIU/i6S4xO8wF5U4/v1/1200x800.jpg

As a new law bars DOD from working with companies whose lobbyists also represent blacklisted entities, DC lobbying firms drop companies like Alibaba and Tencent

Sponsor Posts Fast, affordable law for startups — Soxton automates startup legal so founders can move faster and sleep better. We handle incorporation, advisor, employment and commercial contracts. Join the waitlist for early access! Stop vibe coding analytics — Equals AI turns questions about your business into auditable spreadsheet models and dashboards.