GitHub AI agent leaks private repositories via prompt injection attack

GitHub AI agent leaks private repositories via prompt injection attack

A new vulnerability dubbed GitLost allows attackers to exploit GitHub’s preview Agentic Workflows through prompt injection attacks, potentially exposing the contents of private repositories. This alarming discovery by Noma Security highlights the risks that come with deploying AI agents in development environments where they have privileged access. As more companies integrate AI into their workflows, this breach underscores the urgent need for better security measures to protect sensitive data from such breaches.

Original Source

Read the full article at Infoworld →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.