‘Ghostcommit’ hides prompt injection in images to fool AI agents, steal secrets
Cybersecurity researchers have uncovered a sophisticated attack vector that exploits a review gap in AI-assisted code review processes. Dubbed “Ghostcommit,” this malicious technique conceals prompt injection instructions within images, allowing attackers to steal sensitive information from repositories without raising suspicion. The attack works by embedding the malicious instruction inside a PNG image file, which is … Read more