‘Ghostcommit’ hides prompt injection in images to fool AI agents, steal secrets
**Malicious Image Exploit Leaks Secrets from AI-Coded Repositories** Researchers at the University of Missouri-Kansas City’s ASSET Research Group have unveiled a novel technique for stealing sensitive information from code repositories. Dubbed “Ghostcommit,” this exploit takes advantage of a review gap in popular coding agents to inject malicious instructions into images, which are then executed by … Read more