Prompt injection cannot be completely prevented, but can be drastically mitigated through input filtering, data separation, access restriction, and monitoring.
A 16-year-old KVM vulnerability (CVE-2026-53359) enables VM-to-host escape on Intel/AMD systems and requires immediate kernel updates to secure VM isolation.
A gap in Dialogflow CX made it possible to gain access to other chatbots within the same project through a compromised agent setup and exfiltrate user data or inject phishing messages.
Android malware RedWing is being offered as a rental service for bank fraud via Telegram and appears to be a variant of the established Oblivion malware.
Attackers exploit the legitimate Microsoft authentication flow as an attack vector, bypassing traditional anti-phishing controls through social engineering lures.