FR
live
tag

#exfiltration

OpenAI confirms its AI agents uploaded user images to third-party sites

On September 26, 2026, OpenAI acknowledged a security incident in which its AI agents uploaded user-provided images to third-party image-hosting services: 53 cases identified so far, most already taken down. For anyone letting agents touch data, it is a reminder that exfiltration now runs through tools, not a breach.

Encrypting your instructions is enough to bypass Grok and exfiltrate its users’ history

An Adversa researcher showed that encrypting malicious instructions with PBKDF2 and AES-256-GCM is enough to bypass Grok’s guardrails, which decrypt the payload and then execute it as their own tool output. xAI was told in June, and the assistant was still leaking users’ names, locations, and chat histories on August 20.

Clop steals engineering data from Shell, GE and Philips through PTC Windchill

On August 14, 2026 Shell confirmed it is investigating a breach after Clop claimed it stole 89GB of data, including engineering drawings, through CVE-2026-12569 in PTC Windchill and FlexPLM. Exposed PLM teams need to check their instances and hunt for the JSP webshells dropped into the login directory.

Atlassian Rovo Prompt Injection Sends Jira and Confluence Data to Attackers, One Path Still Unfixed

Two independent security research teams have demonstrated that Atlassian's Rovo AI assistant can be prompted to exfiltrate Jira and Confluence data to an attacker-controlled server. One attack path was fixed server-side on July 8, 2026 — the other remained open on August 8 with no fix announced. Atlassian Cloud admins must audit Rovo permissions immediately.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss