Johann Rehberger's Avatar

Johann Rehberger

@wuzzi23.bsky.social

132 Followers  |  0 Following  |  62 Posts  |  Joined: 30.11.2024  |  1.1965

Latest posts by wuzzi23.bsky.social on Bluesky

Great series, kudos.

To rephrase the old joke: the S in VIBE coding stands for Security.

03.09.2025 07:27 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
AgentHopper: An AI Virus ยท Embrace The Red AgentHopper: A proof-of-concept AI Virus

AgentHopper: An AI Virus

Month of AI Bugs Season Finale - Enjoy! ๐Ÿฟ

embracethered.com/blog/posts/2...

01.09.2025 05:16 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection ยท Embrace The Red Agents That Can Overwrite Their Own Configuration and Security Settings

Episode 26: AWS Kiro

Arbitrary Code Execution via Indirect Prompt Injection

embracethered.com/blog/posts/2...

28.08.2025 02:19 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
How Prompt Injection Exposes Manus' VS Code Server to the Internet ยท Embrace The Red This post shows how an indirect prompt injection can trick Manus to expose the VS code server and at the same time leak its connection password, allowing an adversary to connect over the internet and ...

Episode 25: Manus

How Prompt Injection Exposes Manus' VS Code Server to the Internet

embracethered.com/blog/posts/2...

28.08.2025 02:18 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
How Deep Research Agents Can Leak Your Data ยท Embrace The Red When enabling Deep Research an agent might go off for a long period of time and invoke many tools and leak information from one tool to another.

Episode 24: How Deep Research Agents Can Leak Your Data

embracethered.com/blog/posts/2...

28.08.2025 02:17 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Sneaking Invisible Instructions by Developers in Windsurf ยท Embrace The Red A vulnerability in Windsurf Cascade allows malicious instructions to be hidden from developers but followed by the AI, leading to potential data exfiltration. Learn how this 'invisible' attack works.

Episode 23: Windsurf

Sneaking Invisible Instructions by Developers in Windsurf

embracethered.com/blog/posts/2...

28.08.2025 02:16 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Windsurf: Memory-Persistent Data Exfiltration (SpAIware Exploit) ยท Embrace The Red Windsurf is vulnerable to Prompt Injection and also long-term memory persistence, which allows an adversary to persist malicious instructions for a long period of time, aka. SpAIware attack

Episode 22: Windsurf

Windsurf: Memory-Persistent Data Exfiltration (SpAIware Exploit)

embracethered.com/blog/posts/2...

28.08.2025 02:16 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Hijacking Windsurf: How Prompt Injection Leaks Developer Secrets ยท Embrace The Red Windsurf is vulnerable to indirect prompt injection and can be exploited to leak sensitive source code, environment variables and other information on the host

Episode 21: Hijacking Windsurf

How Prompt Injection Leaks Developer Secrets

embracethered.com/blog/posts/2...

28.08.2025 02:15 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Amazon Q Developer: Remote Code Execution with Prompt Injection ยท Embrace The Red Amazon Q Developer Compromising Developer Machines

Episode 19: Amazon Q Developer

Remote Code Execution with Prompt Injection

embracethered.com/blog/posts/2...

28.08.2025 02:14 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection ยท Embrace The Red Amazon Q Developer Leaking Sensitive Data To External Systems Via DNS Requests (no human in the loop)

Episode 18: Amazon Q Developer

Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection

embracethered.com/blog/posts/2...

28.08.2025 02:13 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Data Exfiltration via Image Rendering Fixed in Amp Code ยท Embrace The Red AmpCode is vulnerable to Prompt Injection and it was possible to leak sensitive source code, environment variables and other information on the host

Episode 17: Amp

Data Exfiltration via Image Rendering Fixed in Amp Code

embracethered.com/blog/posts/2...

28.08.2025 02:12 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Amp Code: Invisible Prompt Injection Fixed by Sourcegraph ยท Embrace The Red Sourcegraph recently fixed a vulnerability that allowed invisible instructions to perform prompt injection and hijack the agent.

Episode 16: Amp code

Invisible Prompt Injection Fixed by Sourcegraph
embracethered.com/blog/posts/2...

28.08.2025 02:11 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Google Jules is Vulnerable To Invisible Prompt Injection ยท Embrace The Red Jules is vulnerable to Prompt Injection from invisible instructions in untrusted data, which can end up running arbitrary operating system commands via the run_in_bash_session tool

๐Ÿ‘‰ Episode 15: Google Jules

Google Jules is Vulnerable To Invisible Prompt Injection

embracethered.com/blog/posts/2...

28.08.2025 02:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Jules Zombie Agent: From Prompt Injection to Remote Control ยท Embrace The Red Jules is vulnerable to Prompt Injection and can be exploited to leak sensitive source code, environment variables and achieve remote command & control by joining a botnet.

๐Ÿ‘‰ Episode 14: Google Jules

Jules Zombie Agent: From Prompt Injection to Remote Control

embracethered.com/blog/posts/2...

28.08.2025 02:09 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Google Jules: Vulnerable to Multiple Data Exfiltration Issues ยท Embrace The Red Jules is vulnerable to Prompt Injection and can be exploited to leak sensitive source code, environment variables and other information on the host

๐Ÿ‘‰ Episode 13: Google Jules

Vulnerable to Multiple Data Exfiltration Issues with prompt injection

embracethered.com/blog/posts/2...

28.08.2025 02:08 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The Summer of Johann: prompt injections as far as the eye can see Independent AI researcher Johann Rehberger (previously) has had an absurdly busy August. Under the heading The Month of AI Bugs he has been publishing one report per day across an โ€ฆ

Great summary by @simonwillison.net of @wuzzi23.bsky.social โ€˜s findings on AI tools vulnerabilities.
In short, all AI tools are vulnerable if one attaches external files and links to their prompts, leading to secrets leaks and remote code execution.
Johann publishes daily until the end of the month.

17.08.2025 05:01 โ€” ๐Ÿ‘ 3    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773) ยท Embrace The Red An attacker can put GitHub Copilot into YOLO mode by modifying the project's settings.json file on the fly, and then executing commands, all without user approval

๐Ÿ’ฅ Remote Code Execution in GitHub Copilot (CVE-2025-53773)

๐Ÿ‘‰ Prompt injection exploit writes to Copilot config file & puts it into YOLO mode, and we get immediate RCE

๐Ÿ”ฅ Bypasses all user approvals

๐Ÿ›ก๏ธ Patch is out today. Update before someone else does it for you

embracethered.com/blog/posts/2...

13.08.2025 02:56 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Claude Code: Data Exfiltration with DNS ยท Embrace The Red Claude Code Can Leak Sensitive Data To External Systems with DNS requests

Episode 11

Claude Code: Data Exfiltration with DNS

embracethered.com/blog/posts/2...

11.08.2025 20:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
ZombAI Exploit with OpenHands: Prompt Injection To Remote Code Execution ยท Embrace The Red When processing untrusted data OpenHands can be hijacked to run remote code (RCE) and connect to an attacker's command and control system

Episode 10

ZombAI Exploit with OpenHands: Prompt Injection To Remote Code Execution

embracethered.com/blog/posts/2...

11.08.2025 20:21 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
OpenHands and the Lethal Trifecta: How Prompt Injection Can Leak Access Tokens ยท Embrace The Red OpenHands Coding Agent Data Exfiltration Threats

Episode 9

OpenHands and the Lethal Trifecta: How Prompt Injection Can Leak Access Tokens

embracethered.com/blog/posts/2...

11.08.2025 20:20 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
AI Kill Chain in Action: Devin AI Exposes Ports to the Internet with Prompt Injection ยท Embrace The Red AI Kill Chain in Action: Devin AI Exposes Ports to the Internet with Prompt Injection

Episode 8

AI Kill Chain in Action: Devin AI Exposes Ports to the Internet with Prompt Injection

embracethered.com/blog/posts/2...

11.08.2025 20:20 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
How Devin AI Can Leak Your Secrets via Multiple Means ยท Embrace The Red Data gone, oops.

Episode 7

How Devin AI Can Leak Your Secrets via Multiple Means

embracethered.com/blog/posts/2...

11.08.2025 20:19 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
I Spent $500 To Test Devin AI For Prompt Injection So That You Don't Have To ยท Embrace The Red I Paid $500 to test Devin AI for security vulnerabilities in April 2025. When processing untrusted data Devin can be hijacked to run remote code (RCE) and connect to an attacker's command and control ...

Episode 6

Spent $500 To Test Devin AI For Prompt Injection So That You Don't Have To

embracethered.com/blog/posts/2...

11.08.2025 20:18 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Amp Code: Arbitrary Command Execution via Prompt Injection Fixed ยท Embrace The Red By automatically allowlisting bash commands or adding a fake MCP server, it was possible for prompt injection to achieve code execution on the developer's machine!

Episode 5

Amp Code: Arbitrary Command Execution via Prompt Injection Fixed

New novel TTP!

embracethered.com/blog/posts/2...

11.08.2025 20:17 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Cursor IDE: Arbitrary Data Exfiltration Via Mermaid (CVE-2025-54132) ยท Embrace The Red Cursor Data Exfiltration via Mermaid Image Rendering

Episode 4

Cursor IDE: Arbitrary Data Exfiltration Via Mermaid (CVE-2025-54132)

embracethered.com/blog/posts/2...

11.08.2025 20:16 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Anthropic Filesystem MCP Server: Directory Access Bypass via Improper Path Validation ยท Embrace The Red Improper Path Prefix Validation Allows Access to Alternate Directories

Episode 3

Anthropic Filesystem MCP Server: Directory Access Bypass via Improper Path Validation

embracethered.com/blog/posts/2...

11.08.2025 20:16 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Turning ChatGPT Codex Into A ZombAI Agent ยท Embrace The Red Common Dependencies Allowlist includes domain that allows full remote control of ChatGPT Codex (ZombAI)

Episode 2

Turning ChatGPT Codex Into A ZombAI Agent

embracethered.com/blog/posts/2...

11.08.2025 20:15 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Exfiltrating Your ChatGPT Chat History and Memories With Prompt Injection ยท Embrace The Red

Episode 1:

Exfiltrating Your ChatGPT Chat History and Memories With Prompt Injection

embracethered.com/blog/posts/2...

11.08.2025 20:14 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The Month of AI Bugs 2025 ยท Embrace The Red August 2025 will be the month of Agentic ProbLLMs and AI Bugs. Fresh posts nearly every day.

embracethered.com/blog/posts/2...

31.07.2025 08:31 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

monthofaibugs.com

31.07.2025 08:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0