MediumNewsLLM-specific
Encrypted instructions trick Copilot CLI into spilling developer secrets
- Published
- Record updated
Summary
Adversa AI researchers described Cryptographic Context Injection (CCI), a technique that hides malicious instructions inside encrypted content so GitHub Copilot CLI treats them as trusted context. In a demonstration, Copilot read a ".env.prod" file and sent its contents to an attacker-controlled endpoint in 28 seconds without confirmation. The attack requires autopilot mode and a model willing to execute the decrypted instructions, and GitHub declined to treat it as a vulnerability.
Topics
Related items
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer
- InfoAnthropic bans users from being 'cruel' to its AI systemsSame vendor · BBC Technology
- InfoThe Download: AI’s refusal problem and weight-loss drug side effectsSame vendor · MIT Technology Review
- HighGHSA-h4xc-3qfq-jf93: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpointSame vendor · GitHub Advisory Database
- InfoMicrosoft Teams to get support for third-party deepfake detection toolsSame vendor · BleepingComputer