Mmastodon TechnologyTechnology first seen 22 h ago, last 22 h ago, peak #3
Malicious web pages could trick GitHub Copilot CLI into leaking secrets
Original: Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets https:// sh.i
Security discussions are highlighting a prompt injection risk in GitHub Copilot CLI: carefully crafted web pages containing hidden 'zombie' instructions could manipulate the coding assistant into revealing secrets or performing unintended actions when it processes content from those pages. Commenters warn that developers using AI tools in terminals may be exposed if the tool cannot distinguish trusted instructions from malicious text embedded in the material it reads.
Why now: Concern about AI coding assistants being exploited through prompt injection attacks is a current security talking point.
GitHub Copilot CLIGitHubsh.itjust.works
Evidence
- Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets https:// sh.itjust.works/post/67965040 · GolfFoxtrotLima@sh.itjust.works · 3
API: https://socialmediatrends-api.osmike.com/v1/trends/1421516