Attackers Use Indirect Prompt Injection to Manipulate AI Systems
Article Content
- •Attackers are embedding malicious commands in emails and documents to manipulate AI systems.
- •The technique, known as indirect prompt injection, poses significant risks to AI applications.
- •OWASP ranks prompt injection as the top security risk for AI, highlighting the need for improved defenses.
In 2025, attackers exploited AI systems by embedding malicious commands in emails and documents, a technique known as indirect prompt injection. This method targets AI tools that process digital communications, potentially affecting numerous organizations. The OWASP has identified prompt injection as the top risk for AI applications, with incidents reported involving Microsoft 365 Copilot. In June 2025, a flaw named EchoLeak was discovered, allowing attackers to extract private data without user interaction. The incidents highlight the vulnerability of AI systems to manipulation through seemingly benign content. As AI becomes more integrated into business processes, the risk of such attacks is expected to grow, necessitating robust security practices. Organizations are advised to implement security measures to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Emerging Threats from AI Prompt Injection Attacks Recent reports highlight two significant AI-related vulnerabilities: prompt injection and a new attack method called Reprompt. Prompt injection allows attackers to embed malicious instructions within documents or prompts, manipulating AI systems to act against user intent. The Reprompt attack, discovered in Microsoft…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…