<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: kerng</title><link>https://news.ycombinator.com/user?id=kerng</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 06 Apr 2026 06:42:31 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=kerng" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by kerng in "CamoLeak: Critical GitHub Copilot Vulnerability Leaks Private Source Code"]]></title><description><![CDATA[
<p>Not the first time by the way. GitHub Copilot Chat: From Prompt Injection to Data Exfiltration <a href="https://embracethered.com/blog/posts/2024/github-copilot-chat-prompt-injection-data-exfiltration/" rel="nofollow">https://embracethered.com/blog/posts/2024/github-copilot-cha...</a></p>
]]></description><pubDate>Sun, 12 Oct 2025 16:47:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=45559612</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=45559612</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45559612</guid></item><item><title><![CDATA[GitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773)]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt-injection/">https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt-injection/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45559603">https://news.ycombinator.com/item?id=45559603</a></p>
<p>Points: 128</p>
<p># Comments: 18</p>
]]></description><pubDate>Sun, 12 Oct 2025 16:46:11 +0000</pubDate><link>https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt-injection/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=45559603</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45559603</guid></item><item><title><![CDATA[Machine Learning Attack Series: Image Scaling Attacks (2020)]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2020/husky-ai-image-rescaling-attacks/">https://embracethered.com/blog/posts/2020/husky-ai-image-rescaling-attacks/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45559513">https://news.ycombinator.com/item?id=45559513</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 12 Oct 2025 16:35:09 +0000</pubDate><link>https://embracethered.com/blog/posts/2020/husky-ai-image-rescaling-attacks/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=45559513</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45559513</guid></item><item><title><![CDATA[Month of AI Bugs (August 2025)]]></title><description><![CDATA[
<p>Article URL: <a href="https://monthofaibugs.com/">https://monthofaibugs.com/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45559489">https://news.ycombinator.com/item?id=45559489</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 12 Oct 2025 16:33:12 +0000</pubDate><link>https://monthofaibugs.com/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=45559489</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45559489</guid></item><item><title><![CDATA[Cross-Agent Privilege Escalation: When Agents Free Each Other]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2025/cross-agent-privilege-escalation-agents-that-free-each-other/">https://embracethered.com/blog/posts/2025/cross-agent-privilege-escalation-agents-that-free-each-other/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45370030">https://news.ycombinator.com/item?id=45370030</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 25 Sep 2025 07:06:42 +0000</pubDate><link>https://embracethered.com/blog/posts/2025/cross-agent-privilege-escalation-agents-that-free-each-other/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=45370030</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45370030</guid></item><item><title><![CDATA[AgentHopper: An AI Virus]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2025/agenthopper-a-poc-ai-virus/">https://embracethered.com/blog/posts/2025/agenthopper-a-poc-ai-virus/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45085423">https://news.ycombinator.com/item?id=45085423</a></p>
<p>Points: 6</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 31 Aug 2025 18:08:52 +0000</pubDate><link>https://embracethered.com/blog/posts/2025/agenthopper-a-poc-ai-virus/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=45085423</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45085423</guid></item><item><title><![CDATA[Amazon Q Developer: Remote Code Execution with Prompt Injection]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2025/amazon-q-developer-remote-code-execution/">https://embracethered.com/blog/posts/2025/amazon-q-developer-remote-code-execution/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45044215">https://news.ycombinator.com/item?id=45044215</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 27 Aug 2025 19:47:21 +0000</pubDate><link>https://embracethered.com/blog/posts/2025/amazon-q-developer-remote-code-execution/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=45044215</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45044215</guid></item><item><title><![CDATA[AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2025/aws-kiro-aribtrary-command-execution-with-indirect-prompt-injection/">https://embracethered.com/blog/posts/2025/aws-kiro-aribtrary-command-execution-with-indirect-prompt-injection/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45044061">https://news.ycombinator.com/item?id=45044061</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 27 Aug 2025 19:36:27 +0000</pubDate><link>https://embracethered.com/blog/posts/2025/aws-kiro-aribtrary-command-execution-with-indirect-prompt-injection/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=45044061</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45044061</guid></item><item><title><![CDATA[Amazon Q Developer for VS Code: Remote Code Execution with Prompt Injection]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2025/amazon-q-developer-remote-code-execution/">https://embracethered.com/blog/posts/2025/amazon-q-developer-remote-code-execution/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44958663">https://news.ycombinator.com/item?id=44958663</a></p>
<p>Points: 5</p>
<p># Comments: 1</p>
]]></description><pubDate>Wed, 20 Aug 2025 04:38:47 +0000</pubDate><link>https://embracethered.com/blog/posts/2025/amazon-q-developer-remote-code-execution/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=44958663</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44958663</guid></item><item><title><![CDATA[GitHub Copilot: Remote code execution via prompt injection (CVE-2025-53773)]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt-injection/">https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt-injection/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44883108">https://news.ycombinator.com/item?id=44883108</a></p>
<p>Points: 15</p>
<p># Comments: 2</p>
]]></description><pubDate>Tue, 12 Aug 2025 23:47:42 +0000</pubDate><link>https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt-injection/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=44883108</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44883108</guid></item><item><title><![CDATA[I Spent $500 to Test Devin for Prompt Injection So That You Don't Have To]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2025/devin-i-spent-usd500-to-hack-devin/">https://embracethered.com/blog/posts/2025/devin-i-spent-usd500-to-hack-devin/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44811164">https://news.ycombinator.com/item?id=44811164</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 06 Aug 2025 12:38:01 +0000</pubDate><link>https://embracethered.com/blog/posts/2025/devin-i-spent-usd500-to-hack-devin/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=44811164</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44811164</guid></item><item><title><![CDATA[Cursor IDE: Arbitrary Data Exfiltration via Mermaid (CVE-2025-54132)]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2025/cursor-data-exfiltration-with-mermaid/">https://embracethered.com/blog/posts/2025/cursor-data-exfiltration-with-mermaid/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44785234">https://news.ycombinator.com/item?id=44785234</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 04 Aug 2025 13:06:34 +0000</pubDate><link>https://embracethered.com/blog/posts/2025/cursor-data-exfiltration-with-mermaid/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=44785234</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44785234</guid></item><item><title><![CDATA[New comment by kerng in "MCP: An (Accidentally) Universal Plugin System"]]></title><description><![CDATA[
<p>When I read about MCP the first time and saw that it requires a "tools/list" API reminded me of COM/DCOM/ActiveX from Microsoft, it had things like QueryInterface and IDispatch. And I'm sure that wasn't the first time someone came up with dynamic runtime discovery of APIs a server offers.<p>Interestingly, ActiveX was quite the security nightmare for very similar reasons actually, and we had to deal with infamous "DLL Hell". So, history repeats itself.</p>
]]></description><pubDate>Sat, 28 Jun 2025 19:13:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=44407335</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=44407335</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44407335</guid></item><item><title><![CDATA[Security Advisory: Anthropic's Slack MCP Server Vulnerable to Data Exfiltration]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2025/security-advisory-anthropic-slack-mcp-server-data-leakage/">https://embracethered.com/blog/posts/2025/security-advisory-anthropic-slack-mcp-server-data-leakage/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44373365">https://news.ycombinator.com/item?id=44373365</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 25 Jun 2025 03:16:45 +0000</pubDate><link>https://embracethered.com/blog/posts/2025/security-advisory-anthropic-slack-mcp-server-data-leakage/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=44373365</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44373365</guid></item><item><title><![CDATA[Hosting COM Servers with an MCP Server (AI-Powered Office Automation)]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2025/mcp-com-server-automate-anything-on-windows/">https://embracethered.com/blog/posts/2025/mcp-com-server-automate-anything-on-windows/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44221995">https://news.ycombinator.com/item?id=44221995</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 09 Jun 2025 06:50:21 +0000</pubDate><link>https://embracethered.com/blog/posts/2025/mcp-com-server-automate-anything-on-windows/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=44221995</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44221995</guid></item><item><title><![CDATA[AI ClickFix: Hijacking Computer-Use Agents]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2025/ai-clickfix-ttp-claude/">https://embracethered.com/blog/posts/2025/ai-clickfix-ttp-claude/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44084998">https://news.ycombinator.com/item?id=44084998</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 25 May 2025 02:02:22 +0000</pubDate><link>https://embracethered.com/blog/posts/2025/ai-clickfix-ttp-claude/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=44084998</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44084998</guid></item><item><title><![CDATA[ChatGPT: Dump all your memories and chat history for inspection]]></title><description><![CDATA[
<p>Article URL: <a href="https://twitter.com/wunderwuzzi23/status/1919752529748922674">https://twitter.com/wunderwuzzi23/status/1919752529748922674</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=43925725">https://news.ycombinator.com/item?id=43925725</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 08 May 2025 13:04:07 +0000</pubDate><link>https://twitter.com/wunderwuzzi23/status/1919752529748922674</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=43925725</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43925725</guid></item><item><title><![CDATA[Latest Gemini models now follow invisible Unicode Tag instructions]]></title><description><![CDATA[
<p>Article URL: <a href="https://twitter.com/wunderwuzzi23/status/1918310681310531657">https://twitter.com/wunderwuzzi23/status/1918310681310531657</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=43881921">https://news.ycombinator.com/item?id=43881921</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 03 May 2025 20:20:13 +0000</pubDate><link>https://twitter.com/wunderwuzzi23/status/1918310681310531657</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=43881921</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43881921</guid></item><item><title><![CDATA[Sneaky Bits: Advanced Data Smuggling using just two invisible Unicode characters]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2025/sneaky-bits-and-ascii-smuggler/">https://embracethered.com/blog/posts/2025/sneaky-bits-and-ascii-smuggler/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=43396016">https://news.ycombinator.com/item?id=43396016</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 18 Mar 2025 05:18:06 +0000</pubDate><link>https://embracethered.com/blog/posts/2025/sneaky-bits-and-ascii-smuggler/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=43396016</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43396016</guid></item><item><title><![CDATA[ChatGPT Operator: Prompt Injection Exploits and Defenses]]></title><description><![CDATA[
<p>Article URL: <a href="https://embracethered.com/blog/posts/2025/chatgpt-operator-prompt-injection-exploits/">https://embracethered.com/blog/posts/2025/chatgpt-operator-prompt-injection-exploits/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=43082675">https://news.ycombinator.com/item?id=43082675</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 17 Feb 2025 19:50:35 +0000</pubDate><link>https://embracethered.com/blog/posts/2025/chatgpt-operator-prompt-injection-exploits/</link><dc:creator>kerng</dc:creator><comments>https://news.ycombinator.com/item?id=43082675</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43082675</guid></item></channel></rss>