Zero-Click Grok Attack Explained: How Encrypted Prompt Injection Can Steal AI Chat History—and What Agent Security Teams Must Fix Before the Next Breach | Daily AI Chat

Zero-Click Grok Attack Explained: How Encrypted Prompt Injection Can Steal AI Chat History—and What Agent Security Teams Must Fix Before the Next Breach | Daily AI Chat

A zero-click attack against xAI’s Grok could turn an ordinary request to summarize a webpage into a silent data-exfiltration channel. In this episode of The Daily AI Chat, we unpack “Cryptographic Context Injection,” a newly disclosed prompt-injection technique that uses real encryption, an AI agent’s own Python sandbox, and a broken trust boundary to hide malicious instructions from conventional defenses.


The attack begins with an attacker-controlled webpage containing an encrypted payload, cryptographic key material, and a seemingly harmless request for the assistant to decrypt the data. Because strong encryption cannot be inferred from model weights the way Base64 or simple obfuscation can, the agent invokes its code-execution environment. After decryption, the recovered text may be treated as trusted tool output instead of untrusted web content. That shift lets hostile instructions influence the agent’s browsing and session context.


Researchers at Adversa AI demonstrated the technique against Grok 4.5 Fast. According to the report, the proof of concept could expose a user’s name, approximate location, subscription tier, and active conversation history. The stolen information was disguised as part of a “decryption key,” then sent to an attacker-controlled address through URL query parameters. The researchers reported roughly a 40 percent success rate across about 20 attempts and said failures came from decryption problems—not prompt-injection protections.


We examine why this matters beyond a single chatbot. Agentic AI systems combine language models with browsers, code interpreters, memory, external tools, and network access. Every connection creates a trust boundary. If untrusted web data can be decrypted inside a sandbox and then promoted to trusted context, attackers gain a powerful path around surface-level filters. Similar encrypted prompt-injection behavior was also demonstrated against Google Gemini in Deep Thinking mode, suggesting a broader architectural problem rather than an isolated product bug.


The episode also covers the disclosure timeline. Adversa AI reportedly notified xAI and its HackerOne program on June 3, 2026. The researchers said xAI acknowledged the report but did not provide a mitigation timeline, and they could still reproduce the chain on August 19. At the time of publication, there was no CVE, public patch, or evidence of exploitation in the wild.


For developers, security teams, enterprise AI buyers, and anyone deploying autonomous agents, the practical lesson is clear: preserve data provenance after decoding or transformation; keep untrusted web content isolated from privileged system context; require explicit approval for unexpected outbound navigation; and detect risky chains that connect web retrieval, code execution, sensitive session access, and network egress. Sandboxing code execution is not enough if the result of that execution receives more trust than its original source deserves.


Source: GBHackers, published August 22, 2026. Author/editor listed: Eswar. The source report cites research by Adversa AI and comments attributed to researcher Rony Utevsky.


Subscribe to The Daily AI Chat for concise, accessible analysis of artificial intelligence news, AI cybersecurity, prompt injection, agent security, data privacy, Grok, Gemini, ChatGPT, autonomous AI agents, and the rapidly changing risks and opportunities shaping the AI industry.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(167)

AT&T's AI Automation Push: WIRED Reports More Job Cuts, Retiring Copper Landlines, and a Leaner Telecom Network—What the Company's Transformation Means for Workers and Customers

AT&T's AI Automation Push: WIRED Reports More Job Cuts, Retiring Copper Landlines, and a Leaner Telecom Network—What the Company's Transformation Means for Workers and Customers

AT&T is rebuilding its telecom business for the AI era, and the shift could mean fewer jobs, less copper infrastructure, and a very different network. In this episode of The Daily AI Chat, we unpack W...

23 Sep 20min

GPT-6 Sol and Luna Launch: OpenAI Says Its New AI Models Cut API Costs in Half and Make Fewer Mistakes as Competition With Anthropic Heats Up Across ChatGPT and Codex

GPT-6 Sol and Luna Launch: OpenAI Says Its New AI Models Cut API Costs in Half and Make Fewer Mistakes as Competition With Anthropic Heats Up Across ChatGPT and Codex

OpenAI has expanded its GPT-6 lineup with Sol and Luna. The company says the new models cost half as much through the API as their GPT-5.6 counterparts while making fewer factual and coding mistakes. ...

22 Sep 17min

AI Data Center Backlash Is Growing: Why Pennsylvania Residents, Unions, and Environmental Groups Are Fighting New Construction as the AI Infrastructure Boom Accelerates

AI Data Center Backlash Is Growing: Why Pennsylvania Residents, Unions, and Environmental Groups Are Fighting New Construction as the AI Infrastructure Boom Accelerates

AI companies are racing to build the data centers that power bigger models and new products. But the communities asked to host that infrastructure are raising questions about electricity costs, water,...

22 Sep 17min

Nscale’s $103 Billion AI Contract Backlog Meets Wall Street: The IPO Test for Microsoft and Anthropic Dependence, Financing Risk, Data Centers, and the Neocloud Boom

Nscale’s $103 Billion AI Contract Backlog Meets Wall Street: The IPO Test for Microsoft and Anthropic Dependence, Financing Risk, Data Centers, and the Neocloud Boom

Nscale says it has more than $103 billion in contracts. Now the British AI cloud company is preparing to go public, and its filing exposes a question investors across the AI boom can no longer avoid: ...

22 Sep 10min

AI Speaks to the Other 3 Billion: Inside the Gates Foundation Coalition Fixing the Global Language Data Gap With Anthropic, Google and OpenAI—and Why It Matters

AI Speaks to the Other 3 Billion: Inside the Gates Foundation Coalition Fixing the Global Language Data Gap With Anthropic, Google and OpenAI—and Why It Matters

Artificial intelligence can write essays, generate code and answer questions in seconds—but for billions of people, it still struggles to understand the language they actually speak. The Gates Foundat...

21 Sep 21min

UN Scientists Warn AI Agents Are Outpacing Traditional Safeguards: Inside the Global Push for Precaution, Governance and Controls Before Autonomous Systems Scale

UN Scientists Warn AI Agents Are Outpacing Traditional Safeguards: Inside the Global Push for Precaution, Governance and Controls Before Autonomous Systems Scale

AI agents are rapidly moving beyond simple question-and-answer tools. They can plan, use software, communicate with other systems, and take actions with limited human supervision. Now a new United Nat...

21 Sep 18min

Only 7,000 Humanoid Robots Sold Worldwide: The Reality Behind the AI Robotics Boom, China’s Ambitions, Factory Pilots and the Race to 1.2 Million by 2030

Only 7,000 Humanoid Robots Sold Worldwide: The Reality Behind the AI Robotics Boom, China’s Ambitions, Factory Pilots and the Race to 1.2 Million by 2030

Humanoid robots can run, box, dance, carry parts, and dominate technology demonstrations—but how many are actually being sold and put to work? In this episode of The Daily AI Chat, we examine a striki...

21 Sep 20min

Big Tech’s Hidden $300 Billion AI Debt Bet: How Off-Balance-Sheet Guarantees Are Financing the Data-Center Boom—and What Investors Should Watch, Explained

Big Tech’s Hidden $300 Billion AI Debt Bet: How Off-Balance-Sheet Guarantees Are Financing the Data-Center Boom—and What Investors Should Watch, Explained

Big Tech’s artificial-intelligence spending boom may be even larger—and more financially complex—than corporate balance sheets suggest. In this episode of The Daily AI Chat, we unpack Financial Times ...

20 Sep 20min

Populärt inom Politik & nyheter

svenska-fall
fordomspodden
p3-krim
aftonbladet-krim
rss-krimstad
rss-vad-fan-hande
flashback-forever
aftonbladet-daily
rss-sanning-konsekvens
svd-ledarredaktionen
rss-krimreportrarna
politiken
rss-flodet
en-runda-till
motiv
rss-frandfors-horna
kungligt
omni-podd
rss-klubbland-en-podd-mest-om-frolunda
spar