AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 764
- Last 90 days
- 324
- Change
- +43%vs 227 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 39 |
764 items
ZombAIs: From Prompt Injection to C2 with Claude Computer Use
Oct 24, 2024MediumNewsSecuritySafetyAnthropic released Claude Computer Use, a beta model and code package that lets Claude control a computer by reading screenshots and running bash commands. The author demonstrates how prompt injection in untrusted data can drive the model to run commands autonomously on a machine, and frames this as a fundamental design problem in LLM-powered applications and agents.
Embrace The RedCVE-2024-43396: Khoj stored XSS through Automation feature task instructions
Aug 20, 2024MediumVulnerabilitySecurityCVE-2024-43396CVE-2024-43396 affects Khoj, an application that creates personal AI agents. The Automation feature does not sanitize the q parameter for the /api/automation endpoint when it is rendered on the page, so a user can inject arbitrary HTML and JavaScript, resulting in Stored XSS (CWE-79).
Fix: This vulnerability is fixed in 1.15.0.
NVD/CVE DatabaseCVE-2024-25639: Khoj cross-site scripting via prompt injection from untrusted documents
Jul 8, 2024MediumVulnerabilitySecurityCVE-2024-25639CVE-2024-25639 affects the Khoj Obsidian, Desktop and Web clients, which inadequately sanitize the AI model's response and user inputs. Untrusted documents, whether indexed by the user or read from the internet via the /online command, can trigger Cross Site Scripting (XSS) through Prompt Injection.
Fix: Fixed in 1.13.0.
NVD/CVE DatabaseThe dangers of AI agents unfurling hyperlinks and what to do about it
Apr 3, 2024MediumNewsSecurityIndustryThe post explains how automatic link unfurling in Slack can enable data exfiltration when untrusted content, such as text injected through a prompt injection attack, causes an LLM-powered Slack App to render a hyperlink with chat data appended. Slack's unfurling request sends that appended data to the third-party server. The author then shows how to disable unfurling in a Slack App's message payload.
Fix: Set "unfurl_links" and "unfurl_media" to False in the message JSON, as shown in the source's create_message function (the source's code example is cut off after "unfurl_media": Fal).
Embrace The Red
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.