IT Security News Hourly Summary 2025-05-24 12h : 3 Posts
4 Articles
4 Articles
IT Security News Hourly Summary 2025-05-24 12h : 3 posts
3 posts were published in the last hour 10:4 : GitLab Duo Vulnerability Let Attack Inject Malicious link & Steal Source Code 10:4 : 184 Million Users’ Passwords Exposed From an Open Directory Controlled by Hackers 10:4 : .Net Based… Read more → The post IT Security News Hourly Summary 2025-05-24 12h : 3 posts appeared first on IT Security News.


GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts
Cybersecurity researchers have discovered an indirect prompt injection flaw in GitLab's artificial intelligence (AI) assistant Duo that could have allowed attackers to steal source code and inject untrusted HTML into its responses, which could then be used to direct victims to malicious websites. GitLab Duo is an artificial intelligence (AI)-powered coding assistant that enables users to write,
Prompt injection flaws in GitLab Duo highlights risks in AI assistants
GitLab’s coding assistant Duo can parse malicious AI prompts hidden in comments, source code, merge request descriptions and commit messages from public repositories, researchers found. This technique allowed them to trick the chatbot into making malicious code suggestions to users, share malicious links and inject rogue HTML code in responses that stealthily leaked code from private projects. “GitLab patched the HTML injection, which is great, …
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
To view factuality data please Upgrade to Premium
Ownership
To view ownership data please Upgrade to Vantage