Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
••
Sichere ProgrammierungCloudflare outage 2019: how one regex caused 27 minutes of 502s(29.09.2026 um 05:46 Uhr)
•
Sichere ProgrammierungHow boxr runs rootless: namespaces, a trampoline, and uid mapping(29.09.2026 um 05:47 Uhr)
••
Sichere ProgrammierungTech Stack for Thumbrella Cloud(29.09.2026 um 05:51 Uhr)
•
AI & KI NachrichtenStructured Outputs vs function calling in the OpenAI API(29.09.2026 um 05:53 Uhr)
•
Sichere ProgrammierungSMS OTP API Ownership: 6 Rate Limit Rules for SaaS Login Recovery(29.09.2026 um 05:55 Uhr)
•
Sichere ProgrammierungHow I Review AI-Generated HTML Before Publishing It(29.09.2026 um 05:58 Uhr)
•
Sichere ProgrammierungAI - Weights(29.09.2026 um 05:59 Uhr)
•••
Sichere ProgrammierungCloudflare outage 2019: how one regex caused 27 minutes of 502s(29.09.2026 um 05:46 Uhr)
•
Sichere ProgrammierungHow boxr runs rootless: namespaces, a trampoline, and uid mapping(29.09.2026 um 05:47 Uhr)
••
Sichere ProgrammierungTech Stack for Thumbrella Cloud(29.09.2026 um 05:51 Uhr)
•
AI & KI NachrichtenStructured Outputs vs function calling in the OpenAI API(29.09.2026 um 05:53 Uhr)
•
Sichere ProgrammierungSMS OTP API Ownership: 6 Rate Limit Rules for SaaS Login Recovery(29.09.2026 um 05:55 Uhr)
•
Sichere ProgrammierungHow I Review AI-Generated HTML Before Publishing It(29.09.2026 um 05:58 Uhr)
•
Sichere ProgrammierungAI - Weights(29.09.2026 um 05:59 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

Security Weekly: Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Hari... - ESW #421

Video von Security Weekly auf YouTube: Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 Interview with Harish Peri from Okta Oktane Preview…

HD Video
Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Hari... - ESW #421
Video abspielen
0
↗ Quelle (youtube.com)
Reagiere als Erste:r — dein Feedback zählt!

Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4

Interview with Harish Peri from Okta



Oktane Preview: building frameworks to secure our Agentic AI future



Like it or not, Agentic AI and protocols like MCP and A2A are getting pushed as the glue to take business process automation to the next level. Giving agents the power and access they need to accomplish these lofty goals is going to be challenging, from a security perspective.



How do put AI agents in the position to perform broad tasks autonomously without granting them all the privileges? How do we avoid making AI agents a gold mine for attackers - the first place they stop once they hack into our companies? These are some examples of the questions Okta aims to answer at this year’s Oktane event, and we aim to kick off the conversations a little early - with this interview!



Segment Resources:



- Check out securityweekly.com/oktane for all our live coverage during the event this year!

- More information about the event and how you can attend can be found here: https://www.okta.com/oktane/

- AI at Work 2025: Securing the AI-powered workforce: https://www.okta.com/newsroom/articles/ai-at-work-2025--securing-the-ai-powered-workforce/



Topic - Indirect Prompt Injection Getting Out of Hand



Reports of indirect prompt injection issues have been around for a while. Of particular note was Michael Bargury's Living off Microsoft Copilot (https://i.blackhat.com/BH-US-24/Presentations/US24-MichaelBargury-LivingoffMicrosofCopilot.pdf) presentation from Black Hat USA 2024. Simply **sending an email** to a Copilot user could make bad stuff happen.



Now, at Black Hat 2025, we've got more: the ability to plunder any data resource connected to ChatGPT (they call these integrations "Connectors") from Tamir Ishay Sharbat at Zenity Labs. The research is titled AgentFlayer: ChatGPT Connectors 0click Attack (https://labs.zenity.io/p/agentflayer-chatgpt-connectors-0click-attack-5b41).



Looks like Google Jules is also vulnerable to what the Embrace the Red blog is calling invisible prompts (https://embracethered.com/blog/posts/2025/amp-code-fixed-invisible-prompt-injection/). Sourcegraph's Amp Code is also vulnerable to the same attack (https://embracethered.com/blog/posts/2025/amp-code-fixed-invisible-prompt-injection/), which encodes instructions to make them invisible.



What's **really** going to ruffle feathers is the fact that all these companies know this stuff is possible, but don't seem to be able to figure out how to prevent it. Ideally, we'd want to be able to distinguish between intended instruction and instructions injected via attachments or some other means outside of the prompt box. I guess that's easier said than done?



News



Finally, in the enterprise security news,



1. Drones are coming for you… to help?

2. One of the most powerful botnets ever goes down

3. Phishing training is still pointless

4. Microsoft sets an alarm on its phone for 8 years from now to do post-quantum stuff

5. vulns galore in commercial ZTNA apps

6. GenAI projects are struggling to make it to production

7. Adblockers could be made illegal - in Germany

8. Windows is getting native Agentic support

9. Automating bug discovery AND remediation?

10. Public service announcement: time is running out for Windows 10



All that and more, on this episode of Enterprise Security Weekly.



Visit https://www.securityweekly.com/esw for all the latest episodes!



Show Notes: https://securityweekly.com/esw-421

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph5 Knoten / 4 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
MITRE ATT&CK Matrix Navigator 14 Taktiken
1 belegte TechnikenLive-Mapping
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Hari... - ESW #421

Thematisch verwandte Begriffe: Oktane, Preview, with, Harish · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-102367 | mall4j through 4.0 contains an insufficient session expiration vulnerab…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag