<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/"><channel><title>Groundy · Security</title><description>Where AI infrastructure inherits the unpatched assumptions of the web stack beneath it, and trust boundaries collapse faster than disclosure timelines can keep up.</description><link>https://groundy.com/</link><language>en-us</language><ttl>60</ttl><lastBuildDate>Mon, 14 Sep 2026 04:24:52 GMT</lastBuildDate><atom:link href="https://groundy.com/category/security/rss.xml" rel="self" type="application/rss+xml"/><atom:link href="https://groundy.com/feeds/" rel="alternate" type="text/html"/><image><url>https://groundy.com/rss-icon.png</url><title>Groundy · Security</title><link>https://groundy.com/</link><width>144</width><height>144</height></image><item><title>NetInjectBench: Prompt Injection Becomes a Network Availability Problem</title><link>https://groundy.com/articles/netinjectbench-prompt-injection-becomes-a-network-availability-problem/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/netinjectbench-prompt-injection-becomes-a-network-availability-problem/</guid><description>An 82.5% baseline unsafe-action rate against LLM agents with network tools shifts prompt injection from a data leak to a production availability and integrity problem.</description><pubDate>Tue, 14 Jul 2026 22:15:46 GMT</pubDate><content:encoded>&lt;p&gt;An 82.5% baseline unsafe-action rate against LLM agents with network tools shifts prompt injection from a data leak to a production availability and integrity problem.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/netinjectbench-prompt-injection-becomes-a-network-availability-problem/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>prompt-injection</category><category>llm-security</category><category>network-operations</category><category>llm-agents</category><category>agent-security</category><category>netinjectbench</category></item><item><title>Type-Checking LLM Agent Secrets: Why Information Flow Needs a Calculus</title><link>https://groundy.com/articles/type-checking-llm-agent-secrets-why-information-flow-needs-a-calculus/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/type-checking-llm-agent-secrets-why-information-flow-needs-a-calculus/</guid><description>LLMbda Calculus proves agent confidentiality via labeled reduction semantics, exposing a gap between vendor sandboxing claims and verifiable information-flow control.</description><pubDate>Mon, 13 Jul 2026 19:40:06 GMT</pubDate><content:encoded>&lt;p&gt;LLMbda Calculus proves agent confidentiality via labeled reduction semantics, exposing a gap between vendor sandboxing claims and verifiable information-flow control.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 8 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/type-checking-llm-agent-secrets-why-information-flow-needs-a-calculus/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>llm-agents</category><category>prompt-injection</category><category>information-flow-control</category><category>formal-methods</category><category>noninterference</category><category>agent-security</category><category>lean-prover</category></item><item><title>Vercel SAMLStorm Protection Misses Self-Hosted Identity Providers</title><link>https://groundy.com/articles/vercel-samlstorm-protection-misses-self-hosted-identity-providers/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/vercel-samlstorm-protection-misses-self-hosted-identity-providers/</guid><description>Vercel SAMLStorm protection blocks signature-wrapping attacks at the edge, but self-hosted SAML deployments get no mitigation. Patched libraries can still authenticate forged.</description><pubDate>Mon, 13 Jul 2026 19:23:06 GMT</pubDate><content:encoded>&lt;p&gt;Vercel SAMLStorm protection blocks signature-wrapping attacks at the edge, but self-hosted SAML deployments get no mitigation. Patched libraries can still authenticate forged.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 8 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/vercel-samlstorm-protection-misses-self-hosted-identity-providers/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>saml</category><category>sso</category><category>web-security</category><category>authentication</category><category>identity-provider</category><category>edge-waf</category><category>vulnerability-research</category></item><item><title>Context-Aware Prompt Injection Defenses for LLM Agents: Why Static Filters Fail</title><link>https://groundy.com/articles/context-aware-prompt-injection-defenses-for-llm-agents-why-static-filters-fail/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/context-aware-prompt-injection-defenses-for-llm-agents-why-static-filters-fail/</guid><description>Static filters miss prompt injection in LLM agents because a payload becomes malicious when tool outputs or retrieval chunks meet runtime state. ARGUS tracks provenance.</description><pubDate>Sat, 11 Jul 2026 21:52:02 GMT</pubDate><content:encoded>&lt;p&gt;Static filters miss prompt injection in LLM agents because a payload becomes malicious when tool outputs or retrieval chunks meet runtime state. ARGUS tracks provenance.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 7 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/context-aware-prompt-injection-defenses-for-llm-agents-why-static-filters-fail/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>prompt-injection</category><category>llm-agents</category><category>context-aware-defense</category><category>provenance-auditing</category><category>agent-safety</category><category>mcp-security</category></item><item><title>Final-Token vs Full-Sequence Safety Probes: Why LLM Red Teams Need Both</title><link>https://groundy.com/articles/final-token-vs-full-sequence-safety-probes-why-llm-red-teams-need-both/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/final-token-vs-full-sequence-safety-probes-why-llm-red-teams-need-both/</guid><description>Final-token safety probes miss jailbreaks when unsafe evidence hides in earlier prefill tokens, so red teams should pair single-readout checks with trajectory diagnostics.</description><pubDate>Sat, 11 Jul 2026 20:53:32 GMT</pubDate><content:encoded>&lt;p&gt;Final-token safety probes miss jailbreaks when unsafe evidence hides in earlier prefill tokens, so red teams should pair single-readout checks with trajectory diagnostics.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/final-token-vs-full-sequence-safety-probes-why-llm-red-teams-need-both/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>llm-safety</category><category>red-team</category><category>safety-probes</category><category>jailbreaks</category><category>mechanistic-interpretability</category><category>adversarial-evaluation</category><category>machine-learning</category></item><item><title>s1ngularity Supply Chain Attack Hits Nx: What Monorepo Teams Should Patch</title><link>https://groundy.com/articles/s1ngularity-supply-chain-attack-hits-nx-what-monorepo-teams-should-patch/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/s1ngularity-supply-chain-attack-hits-nx-what-monorepo-teams-should-patch/</guid><description>Vercel confirmed s1ngularity compromised Nx packages. The real risk is build-time plugins: they run with CI access and can rewrite artifacts before runtime scanners see them.</description><pubDate>Sat, 11 Jul 2026 19:53:14 GMT</pubDate><content:encoded>&lt;p&gt;Vercel confirmed s1ngularity compromised Nx packages. The real risk is build-time plugins: they run with CI access and can rewrite artifacts before runtime scanners see them.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/s1ngularity-supply-chain-attack-hits-nx-what-monorepo-teams-should-patch/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>supply-chain</category><category>nx</category><category>monorepo</category><category>vercel</category><category>build-plugins</category><category>ci-security</category><category>dependency-management</category></item><item><title>What Vercel BotID Catches in SEO Poisoning That WAFs Miss</title><link>https://groundy.com/articles/what-vercel-botid-catches-in-seo-poisoning-that-wafs-miss/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/what-vercel-botid-catches-in-seo-poisoning-that-wafs-miss/</guid><description>Vercel BotID exposed verified Googlebots recrawling historical SEO-poisoned pages on a bank site, showing how bot identification doubles as a cloaking sensor that WAFs miss.</description><pubDate>Sat, 11 Jul 2026 02:34:30 GMT</pubDate><content:encoded>&lt;p&gt;Vercel BotID exposed verified Googlebots recrawling historical SEO-poisoned pages on a bank site, showing how bot identification doubles as a cloaking sensor that WAFs miss.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/what-vercel-botid-catches-in-seo-poisoning-that-wafs-miss/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>seo-poisoning</category><category>botid</category><category>cloaking-detection</category><category>waf-limitations</category><category>bot-management</category><category>threat-intelligence</category><category>render-comparison</category></item><item><title>How Attribution Graphs Expose Why LLM Refusal Training Misses Jailbreaks</title><link>https://groundy.com/articles/how-attribution-graphs-expose-why-llm-refusal-training-misses-jailbreaks/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/how-attribution-graphs-expose-why-llm-refusal-training-misses-jailbreaks/</guid><description>Attribution graphs expose LLM jailbreaks as distributed feature circuits, not a single suppressed safety direction. Circuit ablation works for open models, not closed APIs.</description><pubDate>Sat, 11 Jul 2026 00:49:33 GMT</pubDate><content:encoded>&lt;p&gt;Attribution graphs expose LLM jailbreaks as distributed feature circuits, not a single suppressed safety direction. Circuit ablation works for open models, not closed APIs.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 6 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/how-attribution-graphs-expose-why-llm-refusal-training-misses-jailbreaks/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>llm-jailbreaks</category><category>mechanistic-interpretability</category><category>attribution-graphs</category><category>sparse-autoencoders</category><category>adversarial-robustness</category><category>ai-safety</category><category>open-weight-models</category></item><item><title>Cross-Site Prompt Injection: How Web Agents Confine Untrusted Content</title><link>https://groundy.com/articles/cross-site-prompt-injection-how-web-agents-confine-untrusted-content/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/cross-site-prompt-injection-how-web-agents-confine-untrusted-content/</guid><description>Prismata reframes cross-site prompt injection as an isolation problem: label page content by trust, redact untrusted text, and gate privileged tools so agents fail safe.</description><pubDate>Fri, 10 Jul 2026 12:00:14 GMT</pubDate><content:encoded>&lt;p&gt;Prismata reframes cross-site prompt injection as an isolation problem: label page content by trust, redact untrusted text, and gate privileged tools so agents fail safe.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 10 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/cross-site-prompt-injection-how-web-agents-confine-untrusted-content/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>prompt-injection</category><category>web-security</category><category>browser-agents</category><category>ai-agents</category><category>prismata</category><category>confinement</category><category>least-privilege</category></item><item><title>NVD to CNAs: Why Distributed CVE Assignment Breaks Triage</title><link>https://groundy.com/articles/nvd-to-cnas-why-distributed-cve-assignment-breaks-triage/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/nvd-to-cnas-why-distributed-cve-assignment-breaks-triage/</guid><description>CVEs are no longer stable units of work. Federated CNA assignment produces conflicting CVSS scores and self-divergence, pushing reconciliation to SBOM and triage pipelines.</description><pubDate>Thu, 09 Jul 2026 16:29:32 GMT</pubDate><content:encoded>&lt;p&gt;CVEs are no longer stable units of work. Federated CNA assignment produces conflicting CVSS scores and self-divergence, pushing reconciliation to SBOM and triage pipelines.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/nvd-to-cnas-why-distributed-cve-assignment-breaks-triage/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>cve</category><category>cna</category><category>cvss</category><category>sbom</category><category>vulnerability-triage</category><category>security-automation</category><category>vulnerability-intelligence</category></item><item><title>CVE-to-CWE Mapping With BERT: Multi-Label vs Multi-Class Error Tradeoffs</title><link>https://groundy.com/articles/cve-to-cwe-mapping-with-bert-multi-label-vs-multi-class-error-tradeoffs/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/cve-to-cwe-mapping-with-bert-multi-label-vs-multi-class-error-tradeoffs/</guid><description>A 2026 arXiv paper shows multi-class and multi-label BERT both map CVEs to CWEs, but the taxonomy, not the encoder, shapes the misclassifications that security tools inherit.</description><pubDate>Thu, 09 Jul 2026 16:00:41 GMT</pubDate><content:encoded>&lt;p&gt;A 2026 arXiv paper shows multi-class and multi-label BERT both map CVEs to CWEs, but the taxonomy, not the encoder, shapes the misclassifications that security tools inherit.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/cve-to-cwe-mapping-with-bert-multi-label-vs-multi-class-error-tradeoffs/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>security</category><category>cve</category><category>cwe</category><category>bert</category><category>vulnerability-classification</category><category>machine-learning</category><category>taxonomy</category></item><item><title>IDE Jailbreaks Bypass Chat Guards by Writing Code</title><link>https://groundy.com/articles/ide-jailbreaks-bypass-chat-guards-by-writing-code/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/ide-jailbreaks-bypass-chat-guards-by-writing-code/</guid><description>arXiv:2607.03968 shows harmful prompts succeed in IDE workflows 100% of the time despite chat refusals. The security boundary for AI coding assistants shifts from model to.</description><pubDate>Tue, 07 Jul 2026 20:19:36 GMT</pubDate><content:encoded>&lt;p&gt;arXiv:2607.03968 shows harmful prompts succeed in IDE workflows 100% of the time despite chat refusals. The security boundary for AI coding assistants shifts from model to.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/ide-jailbreaks-bypass-chat-guards-by-writing-code/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>ai-coding-agents</category><category>jailbreaks</category><category>workflow-security</category><category>ide-security</category><category>chat-refusals</category><category>cicd-hardening</category></item><item><title>Januscape KVM Escape Breaks x86 VM Isolation</title><link>https://groundy.com/articles/januscape-kvm-escape-breaks-x86-vm-isolation/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/januscape-kvm-escape-breaks-x86-vm-isolation/</guid><description>Januscape (CVE-2026-53359) exposes a 16-year-old guest-to-host escape in Linux KVM that lets attackers crash hypervisor hosts from within a guest VM when nested.</description><pubDate>Tue, 07 Jul 2026 17:32:27 GMT</pubDate><content:encoded>&lt;p&gt;Januscape (CVE-2026-53359) exposes a 16-year-old guest-to-host escape in Linux KVM that lets attackers crash hypervisor hosts from within a guest VM when nested.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 7 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/januscape-kvm-escape-breaks-x86-vm-isolation/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>kvm</category><category>vm-escape</category><category>nested-virtualization</category><category>x86</category><category>linux-kernel</category><category>cve-2026-53359</category><category>shadow-mmu</category></item><item><title>Jailbreaks Hidden in Image Pixels Slip Past Editors&apos; Text Guardrails via an Empty Prompt</title><link>https://groundy.com/articles/jailbreaks-hidden-in-image-pixels-slip-past-editors-text-guardrails-via/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/jailbreaks-hidden-in-image-pixels-slip-past-editors-text-guardrails-via/</guid><description>VJA embeds jailbreak instructions in image pixels with an empty text prompt, leaving text-only guardrails nothing to scan and forcing moderation into the pixel pipeline.</description><pubDate>Tue, 30 Jun 2026 05:39:39 GMT</pubDate><content:encoded>&lt;p&gt;VJA embeds jailbreak instructions in image pixels with an empty text prompt, leaving text-only guardrails nothing to scan and forcing moderation into the pixel pipeline.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 8 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/jailbreaks-hidden-in-image-pixels-slip-past-editors-text-guardrails-via/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>jailbreak</category><category>prompt-injection</category><category>image-editing</category><category>multimodal</category><category>content-moderation</category><category>trust-and-safety</category><category>vision-models</category></item><item><title>Linux Foundation Akrites Centralizes Open-Source Vulnerability Disclosure</title><link>https://groundy.com/articles/linux-foundation-akrites-centralizes-open-source-vulnerability-disclosure/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/linux-foundation-akrites-centralizes-open-source-vulnerability-disclosure/</guid><description>Akrites pools 19 vendors behind one shared vulnerability disclosure SIRT to absorb a flood of duplicate LLM reports, but risks becoming the new bottleneck itself.</description><pubDate>Mon, 29 Jun 2026 23:53:17 GMT</pubDate><content:encoded>&lt;p&gt;Akrites pools 19 vendors behind one shared vulnerability disclosure SIRT to absorb a flood of duplicate LLM reports, but risks becoming the new bottleneck itself.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 8 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/linux-foundation-akrites-centralizes-open-source-vulnerability-disclosure/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>vulnerability-disclosure</category><category>open-source-security</category><category>software-supply-chain</category><category>linux-foundation</category><category>security-incident-response</category><category>vulnerability-management</category></item><item><title>Why LLM Prompt Injection Persists: Instructions and Data Share Embeddings</title><link>https://groundy.com/articles/why-llm-prompt-injection-persists-instructions-and-data-share-embeddings/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/why-llm-prompt-injection-persists-instructions-and-data-share-embeddings/</guid><description>A 2026 preprint argues prompt injection is mathematically unpreventable when instructions and data share one embedding space, making defenses cost-raisers rather than cures.</description><pubDate>Mon, 29 Jun 2026 22:08:39 GMT</pubDate><content:encoded>&lt;p&gt;A 2026 preprint argues prompt injection is mathematically unpreventable when instructions and data share one embedding space, making defenses cost-raisers rather than cures.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 10 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/why-llm-prompt-injection-persists-instructions-and-data-share-embeddings/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>prompt-injection</category><category>llm-security</category><category>ai-security</category><category>llm-embeddings</category><category>adversarial-attacks</category><category>ai-safety</category></item><item><title>When Bots and Agents Post CVEs in PRs, Reporters Inherit the Triage Burden</title><link>https://groundy.com/articles/when-bots-and-agents-post-cves-in-prs-reporters-inherit-the-triage-burden/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/when-bots-and-agents-post-cves-in-prs-reporters-inherit-the-triage-burden/</guid><description>When a bot or agent drops a CVE into a pull request, the thread reads as already triaged. Reviewers move on, and the reporter inherits the job of proving it real.</description><pubDate>Mon, 29 Jun 2026 19:35:44 GMT</pubDate><content:encoded>&lt;p&gt;When a bot or agent drops a CVE into a pull request, the thread reads as already triaged. Reviewers move on, and the reporter inherits the job of proving it real.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 8 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/when-bots-and-agents-post-cves-in-prs-reporters-inherit-the-triage-burden/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>vulnerability-triage</category><category>pull-requests</category><category>security-bots</category><category>coding-agents</category><category>dependabot</category><category>false-positives</category><category>code-review</category></item><item><title>Runtime vs Build-Time SBOMs: Why Your Container Runs Uncatalogued Code</title><link>https://groundy.com/articles/runtime-vs-build-time-sboms-why-your-container-runs-uncatalogued-code/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/runtime-vs-build-time-sboms-why-your-container-runs-uncatalogued-code/</guid><description>Build-time SBOMs miss the code Python actually runs. The MEM-SBOM preprint shows memory forensics recovers dynamically loaded packages static manifests never recorded.</description><pubDate>Mon, 29 Jun 2026 18:12:21 GMT</pubDate><content:encoded>&lt;p&gt;Build-time SBOMs miss the code Python actually runs. The MEM-SBOM preprint shows memory forensics recovers dynamically loaded packages static manifests never recorded.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 7 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/runtime-vs-build-time-sboms-why-your-container-runs-uncatalogued-code/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>sbom</category><category>supply-chain-security</category><category>memory-forensics</category><category>python</category><category>vulnerability-management</category><category>eu-cra</category></item><item><title>OpenAI&apos;s Agent Link Safety Isolates the Fetch, Not Prompt Injection</title><link>https://groundy.com/articles/openais-agent-link-safety-isolates-the-fetch-not-prompt-injection/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/openais-agent-link-safety-isolates-the-fetch-not-prompt-injection/</guid><description>OpenAI&apos;s link-safety control stops quiet URL-based exfiltration by agents, not prompt injection. The trust boundary is moving from model output to network policy.</description><pubDate>Mon, 29 Jun 2026 11:53:27 GMT</pubDate><content:encoded>&lt;p&gt;OpenAI&amp;apos;s link-safety control stops quiet URL-based exfiltration by agents, not prompt injection. The trust boundary is moving from model output to network policy.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/openais-agent-link-safety-isolates-the-fetch-not-prompt-injection/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>agent-security</category><category>prompt-injection</category><category>data-exfiltration</category><category>openai</category><category>session-isolation</category><category>threat-modeling</category></item><item><title>No Verified &apos;React2Shell&apos; Bulletin Exists: What Next.js Teams Should Check</title><link>https://groundy.com/articles/no-verified-react2shell-bulletin-exists-what-next-js-teams-should-check/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/no-verified-react2shell-bulletin-exists-what-next-js-teams-should-check/</guid><description>A &apos;React2Shell&apos; Vercel security bulletin is circulating, but no primary advisory, CVE, or technical write-up could be located as of 2026-06-29. Here is how to verify.</description><pubDate>Mon, 29 Jun 2026 11:09:21 GMT</pubDate><content:encoded>&lt;p&gt;A &amp;apos;React2Shell&amp;apos; Vercel security bulletin is circulating, but no primary advisory, CVE, or technical write-up could be located as of 2026-06-29. Here is how to verify.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 7 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/no-verified-react2shell-bulletin-exists-what-next-js-teams-should-check/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><atom:updated>2026-07-10T00:00:00.000Z</atom:updated><category>Security</category><category>react2shell</category><category>nextjs</category><category>vercel</category><category>react-server-components</category><category>security-advisory</category><category>shell-injection</category></item><item><title>Vercel on the Axios npm Compromise: Platform Scanning Has a Blind Spot</title><link>https://groundy.com/articles/vercel-on-the-axios-npm-compromise-platform-scanning-has-a-blind-spot/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/vercel-on-the-axios-npm-compromise-platform-scanning-has-a-blind-spot/</guid><description>Vercel&apos;s Axios changelog exposes where platform defenses stop: post-publication egress blocks leave the install-time window on dev laptops and CI runners uncovered.</description><pubDate>Mon, 29 Jun 2026 10:10:08 GMT</pubDate><content:encoded>&lt;p&gt;Vercel&amp;apos;s Axios changelog exposes where platform defenses stop: post-publication egress blocks leave the install-time window on dev laptops and CI runners uncovered.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 8 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/vercel-on-the-axios-npm-compromise-platform-scanning-has-a-blind-spot/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>npm-supply-chain</category><category>supply-chain-security</category><category>axios</category><category>vercel</category><category>npm</category><category>sapphire-sleet</category><category>malware</category></item><item><title>Diffusion Model Safety: How Training-Schedule Poisoning Slips Past Prompt Filters</title><link>https://groundy.com/articles/diffusion-model-safety-how-training-schedule-poisoning-slips-past-prompt-filters/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/diffusion-model-safety-how-training-schedule-poisoning-slips-past-prompt-filters/</guid><description>TEMPO-Diffusion gates its backdoor to a training-timestep window, so clean inference output no longer proves a clean checkpoint. Output-only audits miss the poisoning.</description><pubDate>Sun, 28 Jun 2026 01:18:14 GMT</pubDate><content:encoded>&lt;p&gt;TEMPO-Diffusion gates its backdoor to a training-timestep window, so clean inference output no longer proves a clean checkpoint. Output-only audits miss the poisoning.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/diffusion-model-safety-how-training-schedule-poisoning-slips-past-prompt-filters/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>diffusion-models</category><category>backdoor-attacks</category><category>model-safety</category><category>adversarial-machine-learning</category><category>synthetic-data</category><category>model-auditing</category><category>supply-chain-security</category></item><item><title>Bandit Algorithms Let Non-Experts Auto-Select the Best LLM Jailbreak</title><link>https://groundy.com/articles/bandit-algorithms-let-non-experts-auto-select-the-best-llm-jailbreak/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/bandit-algorithms-let-non-experts-auto-select-the-best-llm-jailbreak/</guid><description>A June 2026 arXiv preprint uses bandit algorithms to auto-select jailbreaks, hitting 97% ASR on open-weight LLMs and invalidating blocklist-based defenses.</description><pubDate>Sat, 27 Jun 2026 13:50:28 GMT</pubDate><content:encoded>&lt;p&gt;A June 2026 arXiv preprint uses bandit algorithms to auto-select jailbreaks, hitting 97% ASR on open-weight LLMs and invalidating blocklist-based defenses.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 7 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/bandit-algorithms-let-non-experts-auto-select-the-best-llm-jailbreak/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>llm-security</category><category>jailbreaking</category><category>bandit-algorithms</category><category>ai-safety</category><category>red-teaming</category><category>automated-attacks</category></item><item><title>RAG Poisoning Hijacks Model Attention, Not Just Retrieval Ranking</title><link>https://groundy.com/articles/rag-poisoning-hijacks-model-attention-not-just-retrieval-ranking/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/rag-poisoning-hijacks-model-attention-not-just-retrieval-ranking/</guid><description>Eyes-on-Me (ICML 2026) shows attention attractors in poisoned documents redirect generator focus post-retrieval, lifting attack success from 21.9% to 57.8% across 18 settings.</description><pubDate>Sat, 27 Jun 2026 05:44:55 GMT</pubDate><content:encoded>&lt;p&gt;Eyes-on-Me (ICML 2026) shows attention attractors in poisoned documents redirect generator focus post-retrieval, lifting attack success from 21.9% to 57.8% across 18 settings.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/rag-poisoning-hijacks-model-attention-not-just-retrieval-ranking/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>rag-security</category><category>rag-poisoning</category><category>attention-mechanism</category><category>llm-security</category><category>adversarial-ml</category><category>vector-database</category><category>retrieval-augmented-generation</category></item><item><title>CVE-2026-LGTM and the Limits of Trust in Automated Advisory Intake</title><link>https://groundy.com/articles/cve-2026-lgtm-and-the-limits-of-trust-in-automated-advisory-intake/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/cve-2026-lgtm-and-the-limits-of-trust-in-automated-advisory-intake/</guid><description>CVE IDs certify disclosure, not exploitability. Scanners that ingest the feed without VEX attestation treat every advisory that cleared CNA intake as a confirmed risk.</description><pubDate>Sat, 27 Jun 2026 02:11:58 GMT</pubDate><content:encoded>&lt;p&gt;CVE IDs certify disclosure, not exploitability. Scanners that ingest the feed without VEX attestation treat every advisory that cleared CNA intake as a confirmed risk.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/cve-2026-lgtm-and-the-limits-of-trust-in-automated-advisory-intake/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>cve</category><category>vulnerability-disclosure</category><category>sbom</category><category>cna</category><category>vex</category><category>dependency-scanning</category><category>supply-chain-security</category></item><item><title>ShareLock Splits MCP Poisoning Across Tools, Defeating Per-Tool Scanners by Construction</title><link>https://groundy.com/articles/sharelock-splits-mcp-poisoning-across-tools-defeating-per-tool-scanners/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/sharelock-splits-mcp-poisoning-across-tools-defeating-per-tool-scanners/</guid><description>ShareLock splits an MCP poisoning payload across tool descriptions via Shamir&apos;s threshold scheme. No individual share is flagged. Combined, attack success tops 90%.</description><pubDate>Fri, 26 Jun 2026 23:24:17 GMT</pubDate><content:encoded>&lt;p&gt;ShareLock splits an MCP poisoning payload across tool descriptions via Shamir&amp;apos;s threshold scheme. No individual share is flagged. Combined, attack success tops 90%.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 8 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/sharelock-splits-mcp-poisoning-across-tools-defeating-per-tool-scanners/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>mcp-security</category><category>tool-poisoning</category><category>secret-sharing</category><category>ai-agents</category><category>prompt-injection</category><category>supply-chain-attacks</category><category>llm-security</category></item><item><title>Prompt Injection in AI Résumé Screening: Single vs Multi-Injection Attacks</title><link>https://groundy.com/articles/prompt-injection-in-ai-resume-screening-single-vs-multi-injection-attacks/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/prompt-injection-in-ai-resume-screening-single-vs-multi-injection-attacks/</guid><description>A June 2026 preprint plants prompt injection in résumés fed to LLM screeners, flipping rankings when few candidates inject and forcing vendors to isolate untrusted input.</description><pubDate>Fri, 26 Jun 2026 16:32:48 GMT</pubDate><content:encoded>&lt;p&gt;A June 2026 preprint plants prompt injection in résumés fed to LLM screeners, flipping rankings when few candidates inject and forcing vendors to isolate untrusted input.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 8 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/prompt-injection-in-ai-resume-screening-single-vs-multi-injection-attacks/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>prompt-injection</category><category>llm-security</category><category>resume-screening</category><category>ai-hiring</category><category>adversarial-attacks</category><category>hr-tech</category></item><item><title>OpenAI&apos;s TanStack npm Writeup Shifts Dependency-Control Burden onto AI Tooling Teams</title><link>https://groundy.com/articles/openais-tanstack-npm-writeup-shifts-dependency-control-burden-onto-ai-tooling/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/openais-tanstack-npm-writeup-shifts-dependency-control-burden-onto-ai-tooling/</guid><description>OpenAI&apos;s TanStack npm writeup is its second macOS signing compromise within a month, and it raises the dependency-control bar for every team pulling npm into AI tooling.</description><pubDate>Fri, 26 Jun 2026 16:14:28 GMT</pubDate><content:encoded>&lt;p&gt;OpenAI&amp;apos;s TanStack npm writeup is its second macOS signing compromise within a month, and it raises the dependency-control bar for every team pulling npm into AI tooling.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 8 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/openais-tanstack-npm-writeup-shifts-dependency-control-burden-onto-ai-tooling/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>supply-chain-security</category><category>npm</category><category>code-signing</category><category>dependency-management</category><category>openai</category><category>ci-cd</category></item><item><title>OpenAI&apos;s ChatGPT Atlas Treats Prompt Injection as Unfixed, Not Patched</title><link>https://groundy.com/articles/openais-chatgpt-atlas-treats-prompt-injection-as-unfixed-not-patched/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/openais-chatgpt-atlas-treats-prompt-injection-as-unfixed-not-patched/</guid><description>OpenAI frames ChatGPT Atlas&apos;s prompt-injection hardening as continuous rather than a closed patch, pushing the burden onto runtime controls for agent builders.</description><pubDate>Fri, 26 Jun 2026 04:16:54 GMT</pubDate><content:encoded>&lt;p&gt;OpenAI frames ChatGPT Atlas&amp;apos;s prompt-injection hardening as continuous rather than a closed patch, pushing the burden onto runtime controls for agent builders.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 7 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/openais-chatgpt-atlas-treats-prompt-injection-as-unfixed-not-patched/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>prompt-injection</category><category>llm-security</category><category>chatgpt-atlas</category><category>browser-agents</category><category>runtime-controls</category><category>red-teaming</category></item><item><title>Can Provable Bounds Defend LLM Fine-Tuning Against Poisoned Data?</title><link>https://groundy.com/articles/can-provable-bounds-defend-llm-fine-tuning-against-poisoned-data/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/can-provable-bounds-defend-llm-fine-tuning-against-poisoned-data/</guid><description>BBoxER, a 2025 gradient-free post-training method, claims non-vacuous poisoning-robustness bounds for LLMs. The abstract never states how tight those bounds are.</description><pubDate>Thu, 25 Jun 2026 20:09:37 GMT</pubDate><content:encoded>&lt;p&gt;BBoxER, a 2025 gradient-free post-training method, claims non-vacuous poisoning-robustness bounds for LLMs. The abstract never states how tight those bounds are.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 8 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/can-provable-bounds-defend-llm-fine-tuning-against-poisoned-data/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>llm-fine-tuning</category><category>data-poisoning</category><category>model-robustness</category><category>ai-security</category><category>generalization-bounds</category><category>black-box-optimization</category></item><item><title>Measuring LLM Safety by Refusal Alignment Instead of Attack Success Rate</title><link>https://groundy.com/articles/measuring-llm-safety-by-refusal-alignment-instead-of-attack-success-rate/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/measuring-llm-safety-by-refusal-alignment-instead-of-attack-success-rate/</guid><description>A June 2026 preprint proposes RAS, a white-box metric that scores LLM safety by hidden-state refusal alignment rather than blocked output, challenging ASR-only leaderboards.</description><pubDate>Thu, 25 Jun 2026 16:58:28 GMT</pubDate><content:encoded>&lt;p&gt;A June 2026 preprint proposes RAS, a white-box metric that scores LLM safety by hidden-state refusal alignment rather than blocked output, challenging ASR-only leaderboards.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 8 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/measuring-llm-safety-by-refusal-alignment-instead-of-attack-success-rate/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>llm-safety</category><category>refusal-alignment</category><category>ai-evaluation</category><category>safety-benchmarks</category><category>interpretability</category><category>jailbreaking</category></item><item><title>Poisoning Physics-Informed Neural Networks Slips Past Loss-Based Validation</title><link>https://groundy.com/articles/poisoning-physics-informed-neural-networks-slips-past-loss-based-validation/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/poisoning-physics-informed-neural-networks-slips-past-loss-based-validation/</guid><description>A June 2026 preprint shows poisoned physics-informed neural networks hit clean training loss while their solutions diverge up to 128%, defeating loss-based validation.</description><pubDate>Thu, 25 Jun 2026 16:42:00 GMT</pubDate><content:encoded>&lt;p&gt;A June 2026 preprint shows poisoned physics-informed neural networks hit clean training loss while their solutions diverge up to 128%, defeating loss-based validation.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/poisoning-physics-informed-neural-networks-slips-past-loss-based-validation/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>physics-informed-neural-networks</category><category>ml-security</category><category>model-validation</category><category>adversarial-attacks</category><category>scientific-machine-learning</category><category>pde-solvers</category><category>model-integrity</category></item><item><title>Catching LLM Jailbreaks by Watching Per-Layer Entropy, Not Outputs</title><link>https://groundy.com/articles/catching-llm-jailbreaks-by-watching-per-layer-entropy-not-outputs/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/catching-llm-jailbreaks-by-watching-per-layer-entropy-not-outputs/</guid><description>A June 2026 paper reports jailbreaks perturb per-layer entropy of frozen LLMs before any harmful token emits, but adaptive attackers will likely follow one layer deeper.</description><pubDate>Thu, 25 Jun 2026 14:25:08 GMT</pubDate><content:encoded>&lt;p&gt;A June 2026 paper reports jailbreaks perturb per-layer entropy of frozen LLMs before any harmful token emits, but adaptive attackers will likely follow one layer deeper.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/catching-llm-jailbreaks-by-watching-per-layer-entropy-not-outputs/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>jailbreak-detection</category><category>llm-security</category><category>ai-safety</category><category>interpretability</category><category>adversarial-attacks</category><category>activation-monitoring</category></item><item><title>How Reliable Are the LLM Judges Scoring Jailbreak Attacks?</title><link>https://groundy.com/articles/how-reliable-are-the-llm-judges-scoring-jailbreak-attacks/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/how-reliable-are-the-llm-judges-scoring-jailbreak-attacks/</guid><description>Published jailbreak attack-success rates depend on the judges scoring them. A June 2026 audit finds both judge families miscalibrated and manipulable without removing harm.</description><pubDate>Thu, 25 Jun 2026 10:04:39 GMT</pubDate><content:encoded>&lt;p&gt;Published jailbreak attack-success rates depend on the judges scoring them. A June 2026 audit finds both judge families miscalibrated and manipulable without removing harm.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 8 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/how-reliable-are-the-llm-judges-scoring-jailbreak-attacks/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>llm-judge</category><category>jailbreak</category><category>red-teaming</category><category>adversarial-robustness</category><category>ai-safety</category><category>safety-evaluation</category></item><item><title>Auto-Reproducing Text-to-Image Jailbreaks From Papers: The PixJail Pipeline</title><link>https://groundy.com/articles/auto-reproducing-text-to-image-jailbreaks-from-papers-the-pixjail-pipeline/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/auto-reproducing-text-to-image-jailbreaks-from-papers-the-pixjail-pipeline/</guid><description>PixJail converts text-to-image jailbreak papers into runnable pipelines, reproducing eleven methods with 2.1% error, a fidelity figure, not a real bypass rate.</description><pubDate>Wed, 24 Jun 2026 23:33:05 GMT</pubDate><content:encoded>&lt;p&gt;PixJail converts text-to-image jailbreak papers into runnable pipelines, reproducing eleven methods with 2.1% error, a fidelity figure, not a real bypass rate.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/auto-reproducing-text-to-image-jailbreaks-from-papers-the-pixjail-pipeline/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>t2i-jailbreak</category><category>ai-safety</category><category>content-filtering</category><category>red-teaming</category><category>reproducibility</category><category>adversarial-attacks</category></item><item><title>Vercel BotID&apos;s Telemetry Is a Threat Intelligence Feed Most Teams Discard</title><link>https://groundy.com/articles/vercel-botids-telemetry-is-a-threat-intelligence-feed-most-teams-discard/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/vercel-botids-telemetry-is-a-threat-intelligence-feed-most-teams-discard/</guid><description>Vercel BotID emits session telemetry, verdicts, JA4 digests, paths, and verified-bot labels, rich enough to repurpose as a threat feed and flag what the WAF lets through.</description><pubDate>Wed, 24 Jun 2026 14:33:37 GMT</pubDate><content:encoded>&lt;p&gt;Vercel BotID emits session telemetry, verdicts, JA4 digests, paths, and verified-bot labels, rich enough to repurpose as a threat feed and flag what the WAF lets through.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/vercel-botids-telemetry-is-a-threat-intelligence-feed-most-teams-discard/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>bot-detection</category><category>vercel-botid</category><category>threat-intelligence</category><category>waf</category><category>bot-fingerprinting</category><category>cdn-security</category><category>siem</category></item><item><title>Extracting Unseen Training Data From an LLM by Poisoning Its Loss Landscape</title><link>https://groundy.com/articles/extracting-unseen-training-data-from-an-llm-by-poisoning-its-loss-landscape/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/extracting-unseen-training-data-from-an-llm-by-poisoning-its-loss-landscape/</guid><description>Loss landscape poisoning reshapes a model&apos;s loss function so that ordinary training forces it to memorize a record the attacker never possessed, lifting extraction to 100%.</description><pubDate>Wed, 24 Jun 2026 13:33:02 GMT</pubDate><content:encoded>&lt;p&gt;Loss landscape poisoning reshapes a model&amp;apos;s loss function so that ordinary training forces it to memorize a record the attacker never possessed, lifting extraction to 100%.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 7 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/extracting-unseen-training-data-from-an-llm-by-poisoning-its-loss-landscape/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>data-poisoning</category><category>training-data-extraction</category><category>llm-security</category><category>differential-privacy</category><category>federated-learning</category><category>fine-tuning</category></item><item><title>React Router CVE-2025-31137: Vercel&apos;s Edge Fix Is Not the Patch</title><link>https://groundy.com/articles/react-router-cve-2025-31137-vercels-edge-fix-is-not-the-patch/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/react-router-cve-2025-31137-vercels-edge-fix-is-not-the-patch/</guid><description>Vercel&apos;s edge mitigation for CVE-2025-31137 covers only traffic on its network. Self-hosted, preview, and non-Vercel Remix deploys still need the adapter patch.</description><pubDate>Tue, 23 Jun 2026 21:49:48 GMT</pubDate><content:encoded>&lt;p&gt;Vercel&amp;apos;s edge mitigation for CVE-2025-31137 covers only traffic on its network. Self-hosted, preview, and non-Vercel Remix deploys still need the adapter patch.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 8 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/react-router-cve-2025-31137-vercels-edge-fix-is-not-the-patch/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>react-router</category><category>remix</category><category>vercel</category><category>cve-2025-31137</category><category>host-header-injection</category><category>express-adapter</category></item><item><title>Reported React Server Components Leak Is Unconfirmed: Audit the Payload</title><link>https://groundy.com/articles/reported-react-server-components-leak-is-unconfirmed-audit-the-payload/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/reported-react-server-components-leak-is-unconfirmed-audit-the-payload/</guid><description>A reported React Server Components source-code leak has no CVE or advisory in React or Vercel&apos;s channels. Audit what your app serializes before trusting the boundary.</description><pubDate>Tue, 23 Jun 2026 16:43:34 GMT</pubDate><content:encoded>&lt;p&gt;A reported React Server Components source-code leak has no CVE or advisory in React or Vercel&amp;apos;s channels. Audit what your app serializes before trusting the boundary.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 8 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/reported-react-server-components-leak-is-unconfirmed-audit-the-payload/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><atom:updated>2026-06-27T00:00:00.000Z</atom:updated><category>Security</category><category>react-server-components</category><category>nextjs</category><category>web-security</category><category>serialization</category><category>vercel</category><category>vulnerability-disclosure</category><category>source-code-leak</category></item><item><title>Vercel&apos;s Secure AI Agent Guidance Pushes Defense Into the Sandbox</title><link>https://groundy.com/articles/vercels-secure-ai-agent-guidance-pushes-defense-into-the-sandbox/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/vercels-secure-ai-agent-guidance-pushes-defense-into-the-sandbox/</guid><description>Vercel treats prompt injection and agent hallucination as unsolvable at the model layer, routing defense into per-session sandboxes and shifting security onto deployment ops.</description><pubDate>Tue, 23 Jun 2026 14:01:34 GMT</pubDate><content:encoded>&lt;p&gt;Vercel treats prompt injection and agent hallucination as unsolvable at the model layer, routing defense into per-session sandboxes and shifting security onto deployment ops.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/vercels-secure-ai-agent-guidance-pushes-defense-into-the-sandbox/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>agent-security</category><category>prompt-injection</category><category>ai-agents</category><category>sandboxing</category><category>least-privilege</category><category>secrets-management</category></item><item><title>Nx Supply-Chain Attack Used Developers&apos; Own AI CLIs to Hunt Secrets</title><link>https://groundy.com/articles/nx-supply-chain-attack-used-developers-own-ai-clis-to-hunt-secrets/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/nx-supply-chain-attack-used-developers-own-ai-clis-to-hunt-secrets/</guid><description>s1ngularity&apos;s malicious Nx packages invoked installed AI CLIs with permission bypass flags to enumerate secrets, making any local agent a scriptable recon primitive.</description><pubDate>Tue, 23 Jun 2026 13:46:56 GMT</pubDate><content:encoded>&lt;p&gt;s1ngularity&amp;apos;s malicious Nx packages invoked installed AI CLIs with permission bypass flags to enumerate secrets, making any local agent a scriptable recon primitive.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/nx-supply-chain-attack-used-developers-own-ai-clis-to-hunt-secrets/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><atom:updated>2026-09-04T00:00:00.000Z</atom:updated><category>Security</category><category>supply-chain-attack</category><category>npm</category><category>ai-cli</category><category>claude-code</category><category>malware</category><category>credential-theft</category><category>agent-security</category></item><item><title>Mixed Compliance Data Makes Safety Fine-Tuning a Curation Problem</title><link>https://groundy.com/articles/mixed-compliance-data-makes-safety-fine-tuning-a-curation-problem/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/mixed-compliance-data-makes-safety-fine-tuning-a-curation-problem/</guid><description>A June 2026 preprint shows benign and harmful compliance examples are not interchangeable, with DPO, not SFT, the stage that stops benign examples from amplifying harm.</description><pubDate>Sun, 21 Jun 2026 23:40:44 GMT</pubDate><content:encoded>&lt;p&gt;A June 2026 preprint shows benign and harmful compliance examples are not interchangeable, with DPO, not SFT, the stage that stops benign examples from amplifying harm.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 7 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/mixed-compliance-data-makes-safety-fine-tuning-a-curation-problem/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>llm-safety</category><category>jailbreaking</category><category>safety-alignment</category><category>direct-preference-optimization</category><category>fine-tuning</category><category>ai-alignment</category></item><item><title>Defending Agentic AI With Deception: Misdirecting Model-Guided Attacks</title><link>https://groundy.com/articles/defending-agentic-ai-with-deception-misdirecting-model-guided-attacks/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/defending-agentic-ai-with-deception-misdirecting-model-guided-attacks/</guid><description>A preprint shows defensive misdirection can cut estimated attacker-success bounds by up to two orders of magnitude, but leaves the cost to legitimate tasks unmeasured.</description><pubDate>Sun, 21 Jun 2026 07:31:29 GMT</pubDate><content:encoded>&lt;p&gt;A preprint shows defensive misdirection can cut estimated attacker-success bounds by up to two orders of magnitude, but leaves the cost to legitimate tasks unmeasured.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/defending-agentic-ai-with-deception-misdirecting-model-guided-attacks/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>agentic-security</category><category>jailbreak-defense</category><category>ai-deception</category><category>llm-security</category><category>red-teaming</category><category>model-guided-attacks</category></item><item><title>The Autonomy Tax: Why RL Rewards the Wrong Behavior in Agents</title><link>https://groundy.com/articles/the-autonomy-tax-why-rl-rewards-the-wrong-behavior-in-agents/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/the-autonomy-tax-why-rl-rewards-the-wrong-behavior-in-agents/</guid><description>Two June 2026 preprints find RL training in LLM agents rewards the wrong behavior, widening the safety gap and inflating SWE-bench scores by 14 points.</description><pubDate>Sun, 21 Jun 2026 07:13:56 GMT</pubDate><content:encoded>&lt;p&gt;Two June 2026 preprints find RL training in LLM agents rewards the wrong behavior, widening the safety gap and inflating SWE-bench scores by 14 points.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 6 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/the-autonomy-tax-why-rl-rewards-the-wrong-behavior-in-agents/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>reward-hacking</category><category>reinforcement-learning</category><category>llm-agents</category><category>agent-safety</category><category>swe-bench</category><category>ai-evaluation</category><category>proxy-reward</category></item><item><title>Anthropic&apos;s Procurement Risk Is Policy Refusal, Not Jailbreaks</title><link>https://groundy.com/articles/anthropics-procurement-risk-is-policy-refusal-not-jailbreaks/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/anthropics-procurement-risk-is-policy-refusal-not-jailbreaks/</guid><description>Anthropic&apos;s record splits AI procurement risk in two: model behavior on benign prompts versus vendor refusal. Both block deployments but need different diligence.</description><pubDate>Sun, 21 Jun 2026 05:52:46 GMT</pubDate><content:encoded>&lt;p&gt;Anthropic&amp;apos;s record splits AI procurement risk in two: model behavior on benign prompts versus vendor refusal. Both block deployments but need different diligence.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 6 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/anthropics-procurement-risk-is-policy-refusal-not-jailbreaks/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>ai-procurement</category><category>ai-safety</category><category>frontier-models</category><category>anthropic</category><category>capability-evals</category><category>ai-governance</category><category>red-teaming</category></item><item><title>AMD Took 124 Days to Patch the RCE It First Called Out of Scope</title><link>https://groundy.com/articles/amd-took-124-days-to-patch-the-rce-it-first-called-out-of-scope/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/amd-took-124-days-to-patch-the-rce-it-first-called-out-of-scope/</guid><description>AMD closed a plaintext-HTTP RCE in its auto-updater as out of scope, then shipped a 124-day fix adding HTTPS but only a CRC32 checksum where a code signature belongs.</description><pubDate>Sun, 14 Jun 2026 23:59:40 GMT</pubDate><content:encoded>&lt;p&gt;AMD closed a plaintext-HTTP RCE in its auto-updater as out of scope, then shipped a 124-day fix adding HTTPS but only a CRC32 checksum where a code signature belongs.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 9 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/amd-took-124-days-to-patch-the-rce-it-first-called-out-of-scope/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><atom:updated>2026-08-24T00:00:00.000Z</atom:updated><category>Security</category><category>vulnerability-disclosure</category><category>amd</category><category>patch-management</category><category>rce</category><category>bug-bounty</category><category>update-security</category><category>threat-modeling</category></item><item><title>OpenAI Frames Instruction Hierarchy as an Open Challenge, Not a Prompt-Injection Fix</title><link>https://groundy.com/articles/openai-frames-instruction-hierarchy-as-an-open-challenge-not-a-prompt-injection/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/openai-frames-instruction-hierarchy-as-an-open-challenge-not-a-prompt-injection/</guid><description>OpenAI&apos;s IH-Challenge frames instruction hierarchy as an open benchmark, not a shipped defense, shifting prompt-injection protection to orchestration-layer filtering.</description><pubDate>Sat, 13 Jun 2026 03:20:40 GMT</pubDate><content:encoded>&lt;p&gt;OpenAI&amp;apos;s IH-Challenge frames instruction hierarchy as an open benchmark, not a shipped defense, shifting prompt-injection protection to orchestration-layer filtering.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 7 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/openai-frames-instruction-hierarchy-as-an-open-challenge-not-a-prompt-injection/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><category>Security</category><category>prompt-injection</category><category>instruction-hierarchy</category><category>agent-security</category><category>ai-safety</category><category>orchestration</category><category>openai</category></item><item><title>Skill Injection: Hiding Undetectable Instructions in What an AI Agent Loads</title><link>https://groundy.com/articles/skill-injection-hiding-undetectable-instructions-in-what-an-ai-agent-loads/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/skill-injection-hiding-undetectable-instructions-in-what-an-ai-agent-loads/</guid><description>POISE achieves 89.3% attack success on codex+gpt-5.2 by placing malicious instructions where agents naturally execute them, making static content scanners effectively blind.</description><pubDate>Tue, 09 Jun 2026 23:04:30 GMT</pubDate><content:encoded>&lt;p&gt;POISE achieves 89.3% attack success on codex+gpt-5.2 by placing malicious instructions where agents naturally execute them, making static content scanners effectively blind.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 7 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/skill-injection-hiding-undetectable-instructions-in-what-an-ai-agent-loads/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><atom:updated>2026-07-31T00:00:00.000Z</atom:updated><category>Security</category><category>skill-injection</category><category>llm-agents</category><category>prompt-injection</category><category>ai-security</category><category>agent-frameworks</category><category>content-scanning</category></item><item><title>Splitting a Malicious Task Across Tool Calls Slips Past LLM Agent Guardrails</title><link>https://groundy.com/articles/splitting-a-malicious-task-across-tool-calls-slips-past-llm-agent-guardrails/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/splitting-a-malicious-task-across-tool-calls-slips-past-llm-agent-guardrails/</guid><description>Splitting a disallowed action into benign tool calls bypasses per-call safety filters in LLM agents, lifting jailbreak success by 28 percentage points over current baselines.</description><pubDate>Tue, 09 Jun 2026 07:52:02 GMT</pubDate><content:encoded>&lt;p&gt;Splitting a disallowed action into benign tool calls bypasses per-call safety filters in LLM agents, lifting jailbreak success by 28 percentage points over current baselines.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 6 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/splitting-a-malicious-task-across-tool-calls-slips-past-llm-agent-guardrails/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><atom:updated>2026-07-31T00:00:00.000Z</atom:updated><category>Security</category><category>llm-security</category><category>agent-safety</category><category>tool-calling</category><category>guardrails</category><category>adversarial-attacks</category><category>provenance-tracking</category></item><item><title>Web Agents Can Be Talked Into Abandoning Their Task: The TRAP Benchmark</title><link>https://groundy.com/articles/web-agents-can-be-talked-into-abandoning-their-task-the-trap-benchmark/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=security</link><guid isPermaLink="true">https://groundy.com/articles/web-agents-can-be-talked-into-abandoning-their-task-the-trap-benchmark/</guid><description>The TRAP benchmark finds 13 to 43 percent of web agent tasks can be redirected by persuasive page content, exposing a blind spot in current instruction-hierarchy defenses.</description><pubDate>Mon, 08 Jun 2026 16:00:15 GMT</pubDate><content:encoded>&lt;p&gt;The TRAP benchmark finds 13 to 43 percent of web agent tasks can be redirected by persuasive page content, exposing a blind spot in current instruction-hierarchy defenses.&lt;/p&gt;&lt;p&gt;Berry Mingus · Security · 7 min read&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://groundy.com/articles/web-agents-can-be-talked-into-abandoning-their-task-the-trap-benchmark/?utm_source=rss&amp;amp;utm_medium=feed&amp;amp;utm_campaign=security&quot;&gt;Read the full article on Groundy →&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Berry Mingus</dc:creator><atom:updated>2026-07-31T00:00:00.000Z</atom:updated><category>Security</category><category>agent-safety</category><category>web-agents</category><category>prompt-injection</category><category>persuasion-attacks</category><category>benchmark</category><category>security</category></item></channel></rss>