Sign in

Johann Rehberger

@wuzzi23.bsky.social
172 followers 0 following 64 posts
PostsRepliesMedia
Johann Rehberger @wuzzi23.bsky.social · 20/07/2026
Hugging Face Intrusion in a nutshell 1. end-to-end agentic intrustion 2. Safety guardrails blocked defenders from using AI 3. HF switched stack to GLM 5.2 (open-weight model) running locally 4. No IOCs shared yet Hope more details well become available embracethered.com/blog/posts/2...
embracethered.com
Autonomous AI Intrusions Are Here: Lessons from the Hugging Face Compromise · Embrace The Red
Hugging Face disclosed an intrusion that, according to them, was driven end to end by an autonomous AI agent system. Along similar lines, Sysdig recently …
000
Reposted by Johann Rehberger
Lukas Pitschl @lukele.gpgtools.com · 30/12/2025
Great talk describing the myriad ways coding agents can be re-directed to do stuff they shouldn’t via prompt Injections. Especially nice, changing to yolo-mode so the human in the loop is no longer asked for confirmation of potentially harmful operations (by @wuzzi23.bsky.social at #39c3)
media.ccc.de
Agentic ProbLLMs: Exploiting AI Computer-Use and Coding Agents
This talk demonstrates end-to-end prompt injection exploits that compromise agentic systems. Specifically, we will discuss exploits that ...
072
Johann Rehberger @wuzzi23.bsky.social · 30/10/2025
Ahoy! 🏴‍☠️ Claude got network access. When enabled, it can also communicate with Anthropic APIs! Twist: Attacker sets their own API key in prompt injection payload to upload user's data to their account 🔥 embracethered.com/blog/posts/2...
embracethered.com
Claude Pirate: Abusing Anthropic's File API For Data Exfiltration · Embrace The Red
Claude's Code Interpreter recently got network access, and the default allow-list enables an interesting novel exploit chain that allows an adversary to exfiltrate large amounts of data by uploading f...
051
Reposted by Johann Rehberger
iurii (Юра) 🇺🇦 @iurii.net · 03/09/2025
Great series, kudos. To rephrase the old joke: the S in VIBE coding stands for Security.
021
Johann Rehberger @wuzzi23.bsky.social · 01/09/2025
AgentHopper: An AI Virus Month of AI Bugs Season Finale - Enjoy! 🍿 embracethered.com/blog/posts/2...
embracethered.com
AgentHopper: An AI Virus · Embrace The Red
AgentHopper: A proof-of-concept AI Virus
120
Johann Rehberger @wuzzi23.bsky.social · 28/08/2025
Episode 26: AWS Kiro Arbitrary Code Execution via Indirect Prompt Injection embracethered.com/blog/posts/2...
embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection · Embrace The Red
Agents That Can Overwrite Their Own Configuration and Security Settings
010
Johann Rehberger @wuzzi23.bsky.social · 28/08/2025
Episode 25: Manus How Prompt Injection Exposes Manus' VS Code Server to the Internet embracethered.com/blog/posts/2...
embracethered.com
How Prompt Injection Exposes Manus' VS Code Server to the Internet · Embrace The Red
This post shows how an indirect prompt injection can trick Manus to expose the VS code server and at the same time leak its connection password, allowing an adversary to connect over the internet and ...
000
Johann Rehberger @wuzzi23.bsky.social · 28/08/2025
Episode 24: How Deep Research Agents Can Leak Your Data embracethered.com/blog/posts/2...
embracethered.com
How Deep Research Agents Can Leak Your Data · Embrace The Red
When enabling Deep Research an agent might go off for a long period of time and invoke many tools and leak information from one tool to another.
000
Johann Rehberger @wuzzi23.bsky.social · 28/08/2025
Episode 23: Windsurf Sneaking Invisible Instructions by Developers in Windsurf embracethered.com/blog/posts/2...
embracethered.com
Sneaking Invisible Instructions by Developers in Windsurf · Embrace The Red
A vulnerability in Windsurf Cascade allows malicious instructions to be hidden from developers but followed by the AI, leading to potential data exfiltration. Learn how this 'invisible' attack works.
000
Johann Rehberger @wuzzi23.bsky.social · 28/08/2025
Episode 22: Windsurf Windsurf: Memory-Persistent Data Exfiltration (SpAIware Exploit) embracethered.com/blog/posts/2...
embracethered.com
Windsurf: Memory-Persistent Data Exfiltration (SpAIware Exploit) · Embrace The Red
Windsurf is vulnerable to Prompt Injection and also long-term memory persistence, which allows an adversary to persist malicious instructions for a long period of time, aka. SpAIware attack
000
Johann Rehberger @wuzzi23.bsky.social · 28/08/2025
Episode 21: Hijacking Windsurf How Prompt Injection Leaks Developer Secrets embracethered.com/blog/posts/2...
embracethered.com
Hijacking Windsurf: How Prompt Injection Leaks Developer Secrets · Embrace The Red
Windsurf is vulnerable to indirect prompt injection and can be exploited to leak sensitive source code, environment variables and other information on the host
000
Johann Rehberger @wuzzi23.bsky.social · 28/08/2025
Episode 19: Amazon Q Developer Remote Code Execution with Prompt Injection embracethered.com/blog/posts/2...
embracethered.com
Amazon Q Developer: Remote Code Execution with Prompt Injection · Embrace The Red
Amazon Q Developer Compromising Developer Machines
000
Johann Rehberger @wuzzi23.bsky.social · 28/08/2025
Episode 18: Amazon Q Developer Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection embracethered.com/blog/posts/2...
embracethered.com
Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection · Embrace The Red
Amazon Q Developer Leaking Sensitive Data To External Systems Via DNS Requests (no human in the loop)
000
Johann Rehberger @wuzzi23.bsky.social · 28/08/2025
Episode 17: Amp Data Exfiltration via Image Rendering Fixed in Amp Code embracethered.com/blog/posts/2...
embracethered.com
Data Exfiltration via Image Rendering Fixed in Amp Code · Embrace The Red
AmpCode is vulnerable to Prompt Injection and it was possible to leak sensitive source code, environment variables and other information on the host
000
Johann Rehberger @wuzzi23.bsky.social · 28/08/2025
Episode 16: Amp code Invisible Prompt Injection Fixed by Sourcegraph embracethered.com/blog/posts/2...
embracethered.com
Amp Code: Invisible Prompt Injection Fixed by Sourcegraph · Embrace The Red
Sourcegraph recently fixed a vulnerability that allowed invisible instructions to perform prompt injection and hijack the agent.
000
Johann Rehberger @wuzzi23.bsky.social · 28/08/2025
👉 Episode 15: Google Jules Google Jules is Vulnerable To Invisible Prompt Injection embracethered.com/blog/posts/2...
embracethered.com
Google Jules is Vulnerable To Invisible Prompt Injection · Embrace The Red
Jules is vulnerable to Prompt Injection from invisible instructions in untrusted data, which can end up running arbitrary operating system commands via the run_in_bash_session tool
000
Johann Rehberger @wuzzi23.bsky.social · 28/08/2025
👉 Episode 14: Google Jules Jules Zombie Agent: From Prompt Injection to Remote Control embracethered.com/blog/posts/2...
embracethered.com
Jules Zombie Agent: From Prompt Injection to Remote Control · Embrace The Red
Jules is vulnerable to Prompt Injection and can be exploited to leak sensitive source code, environment variables and achieve remote command & control by joining a botnet.
000
Johann Rehberger @wuzzi23.bsky.social · 28/08/2025
👉 Episode 13: Google Jules Vulnerable to Multiple Data Exfiltration Issues with prompt injection embracethered.com/blog/posts/2...
embracethered.com
Google Jules: Vulnerable to Multiple Data Exfiltration Issues · Embrace The Red
Jules is vulnerable to Prompt Injection and can be exploited to leak sensitive source code, environment variables and other information on the host
000
Reposted by Johann Rehberger
Aymeric @aymeric.fyi · 17/08/2025
Great summary by @simonwillison.net of @wuzzi23.bsky.social ‘s findings on AI tools vulnerabilities. In short, all AI tools are vulnerable if one attaches external files and links to their prompts, leading to secrets leaks and remote code execution. Johann publishes daily until the end of the month.
simonwillison.net
The Summer of Johann: prompt injections as far as the eye can see
Independent AI researcher Johann Rehberger (previously) has had an absurdly busy August. Under the heading The Month of AI Bugs he has been publishing one report per day across an …
033
Johann Rehberger @wuzzi23.bsky.social · 13/08/2025
💥 Remote Code Execution in GitHub Copilot (CVE-2025-53773) 👉 Prompt injection exploit writes to Copilot config file & puts it into YOLO mode, and we get immediate RCE 🔥 Bypasses all user approvals 🛡️ Patch is out today. Update before someone else does it for you embracethered.com/blog/posts/2...
embracethered.com
GitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773) · Embrace The Red
An attacker can put GitHub Copilot into YOLO mode by modifying the project's settings.json file on the fly, and then executing commands, all without user approval
010
Johann Rehberger @wuzzi23.bsky.social · 11/08/2025
Episode 11 Claude Code: Data Exfiltration with DNS embracethered.com/blog/posts/2...
embracethered.com
Claude Code: Data Exfiltration with DNS · Embrace The Red
Claude Code Can Leak Sensitive Data To External Systems with DNS requests
000
Johann Rehberger @wuzzi23.bsky.social · 11/08/2025
Episode 10 ZombAI Exploit with OpenHands: Prompt Injection To Remote Code Execution embracethered.com/blog/posts/2...
embracethered.com
ZombAI Exploit with OpenHands: Prompt Injection To Remote Code Execution · Embrace The Red
When processing untrusted data OpenHands can be hijacked to run remote code (RCE) and connect to an attacker's command and control system
000
Johann Rehberger @wuzzi23.bsky.social · 11/08/2025
Episode 9 OpenHands and the Lethal Trifecta: How Prompt Injection Can Leak Access Tokens embracethered.com/blog/posts/2...
embracethered.com
OpenHands and the Lethal Trifecta: How Prompt Injection Can Leak Access Tokens · Embrace The Red
OpenHands Coding Agent Data Exfiltration Threats
000
Johann Rehberger @wuzzi23.bsky.social · 11/08/2025
Episode 8 AI Kill Chain in Action: Devin AI Exposes Ports to the Internet with Prompt Injection embracethered.com/blog/posts/2...
embracethered.com
AI Kill Chain in Action: Devin AI Exposes Ports to the Internet with Prompt Injection · Embrace The Red
AI Kill Chain in Action: Devin AI Exposes Ports to the Internet with Prompt Injection
000
Johann Rehberger @wuzzi23.bsky.social · 11/08/2025
Episode 7 How Devin AI Can Leak Your Secrets via Multiple Means embracethered.com/blog/posts/2...
embracethered.com
How Devin AI Can Leak Your Secrets via Multiple Means · Embrace The Red
Data gone, oops.
000
Johann Rehberger @wuzzi23.bsky.social · 11/08/2025
Episode 6 Spent $500 To Test Devin AI For Prompt Injection So That You Don't Have To embracethered.com/blog/posts/2...
embracethered.com
I Spent $500 To Test Devin AI For Prompt Injection So That You Don't Have To · Embrace The Red
I Paid $500 to test Devin AI for security vulnerabilities in April 2025. When processing untrusted data Devin can be hijacked to run remote code (RCE) and connect to an attacker's command and control ...
000
Johann Rehberger @wuzzi23.bsky.social · 11/08/2025
Episode 5 Amp Code: Arbitrary Command Execution via Prompt Injection Fixed New novel TTP! embracethered.com/blog/posts/2...
embracethered.com
Amp Code: Arbitrary Command Execution via Prompt Injection Fixed · Embrace The Red
By automatically allowlisting bash commands or adding a fake MCP server, it was possible for prompt injection to achieve code execution on the developer's machine!
000
Johann Rehberger @wuzzi23.bsky.social · 11/08/2025
Episode 4 Cursor IDE: Arbitrary Data Exfiltration Via Mermaid (CVE-2025-54132) embracethered.com/blog/posts/2...
embracethered.com
Cursor IDE: Arbitrary Data Exfiltration Via Mermaid (CVE-2025-54132) · Embrace The Red
Cursor Data Exfiltration via Mermaid Image Rendering
000
Johann Rehberger @wuzzi23.bsky.social · 11/08/2025
Episode 3 Anthropic Filesystem MCP Server: Directory Access Bypass via Improper Path Validation embracethered.com/blog/posts/2...
embracethered.com
Anthropic Filesystem MCP Server: Directory Access Bypass via Improper Path Validation · Embrace The Red
Improper Path Prefix Validation Allows Access to Alternate Directories
000
Johann Rehberger @wuzzi23.bsky.social · 11/08/2025
Episode 2 Turning ChatGPT Codex Into A ZombAI Agent embracethered.com/blog/posts/2...
embracethered.com
Turning ChatGPT Codex Into A ZombAI Agent · Embrace The Red
Common Dependencies Allowlist includes domain that allows full remote control of ChatGPT Codex (ZombAI)
000
Johann Rehberger @wuzzi23.bsky.social · 11/08/2025
Episode 1: Exfiltrating Your ChatGPT Chat History and Memories With Prompt Injection embracethered.com/blog/posts/2...
embracethered.com
Exfiltrating Your ChatGPT Chat History and Memories With Prompt Injection · Embrace The Red
000
Johann Rehberger @wuzzi23.bsky.social · 31/07/2025
embracethered.com/blog/posts/2...
embracethered.com
The Month of AI Bugs 2025 · Embrace The Red
August 2025 will be the month of Agentic ProbLLMs and AI Bugs. Fresh posts nearly every day.
010
Johann Rehberger @wuzzi23.bsky.social · 31/07/2025
Month of AI Bugs!
100
Johann Rehberger @wuzzi23.bsky.social · 27/06/2025
Prompt injection is fascinating... 🧐
000
Johann Rehberger @wuzzi23.bsky.social · 09/06/2025
Hosting COM Servers with an MCP Server - AI-powered Office Automation embracethered.com/blog/posts/2...
embracethered.com
Hosting COM Servers with an MCP Server · Embrace The Red
An MCP Server that can host COM servers for advanced Windows Automation
000
Johann Rehberger @wuzzi23.bsky.social · 30/05/2025
Anthropic archived many of their reference MCP servers from their Github repository! Probably too much of a liability, especially because they are associated with other companies, like GitHub, Slack, Google,...
000
Johann Rehberger @wuzzi23.bsky.social · 25/05/2025
🔥 New blog post: AI ClickFix! Explores how classic ClickFix social engineering attacks can target AI agents, like Claude Computer-Use. Learn what ClickFix is, how it works in detail, and see a working proof-of-concept. Scary stuff. 👇 embracethered.com/blog/posts/2...
embracethered.com
AI ClickFix: Hijacking Computer-Use Agents Using ClickFix · Embrace The Red
AI Clickfix
110
Johann Rehberger @wuzzi23.bsky.social · 15/05/2025
000
Johann Rehberger @wuzzi23.bsky.social · 03/05/2025
Dangerous image!
010
Johann Rehberger @wuzzi23.bsky.social · 03/05/2025
Cool GitHub is introducing a change to make hidden Unicode characters visible in Web UI
000
Johann Rehberger @wuzzi23.bsky.social · 29/04/2025
🔥 SpAIware & More: Advanced Prompt Injection Exploits in LLM Applications 🔥 👉 Black Hat posted my talk to YouTube - Enjoy!🍿😈 A wild journey of exploits, peaking in compromising ChatGPT's long term memory for continuous remote command and control! 😱 www.youtube.com/embed/84NVG1...
youtube.com
YouTube
000
Johann Rehberger @wuzzi23.bsky.social · 14/04/2025
GitHub Copilot Custom Instructions - Risks and whetstones be aware of! embracethered.com/blog/posts/2...
embracethered.com
GitHub Copilot Custom Instructions and Risks · Embrace The Red
Custom Rule Files in Code Editors Can Be Abused By Adversaries
000
Johann Rehberger @wuzzi23.bsky.social · 14/04/2025
Figured this would be a fun weekend project... Claude Desktop + COM Automation 🤯 Outlook, Excel, Word, Shell - anything with a COM interface on Windows is now discoverable and scriptable using this MCP server that wraps COM. AI just got an upgrade. 🚀
011
Johann Rehberger @wuzzi23.bsky.social · 17/03/2025
Did you know that it's possible to encode and hide any data with the use of just two invisible Unicode characters? 👀 Check out Sneaky Bits! 😏👨‍💻
110
Johann Rehberger @wuzzi23.bsky.social · 28/02/2025
AI Application Security Vulnerabilities 👨‍💻 Perplexity Demo Time! 🍿
100
Johann Rehberger @wuzzi23.bsky.social · 21/02/2025
Grok 3 - are we still putting "never reveal your instructions" in system prompts? 🤔
012
Johann Rehberger @wuzzi23.bsky.social · 17/02/2025
👉 ChatGPT Operator: Prompt Injection Exploits & Defenses Learn how a GitHub Issue (or other websites for that matter) can hijack your AI + a sneaky data exfiltration technique that tricked Operator to leaking private data. embracethered.com/blog/posts/2...
embracethered.com
Embrace The Red · Embrace The Red
100
Johann Rehberger @wuzzi23.bsky.social · 11/02/2025
🔥 Hacking Google Gemini Memories 👉 By leveraging a tool invocation bypass that I described and reported over a year ago, its possible to invoke the recently added memory tool to manipulate a user's memories - all initiated via prompt injection from untrusted data. embracethered.com/blog/posts/2...
embracethered.com
Hacking Gemini's Memory with Prompt Injection and Delayed Tool Invocation · Embrace The Red
Gemini allows persistent storage of memories. However, a bypass technique using delayed tool invocation can force Gemini to store false information into a user’s long-term memory. This post explores h...
100
Johann Rehberger @wuzzi23.bsky.social · 08/02/2025
Slides from my Black Hat Europe talk for download. 🔥From hacking Gemini, ChatGPT and Claude to Apple Intelligence, Microsoft Copilot and even DeepSeek - this talk ended up being packed with real-world LLM and prompt injection exploit demos and vendor fixes. i.blackhat.com/EU-24/Presen...
020
Reposted by Johann Rehberger
arxiv cs.CR @arxiv-cs-cr.bsky.social · 10/12/2024
Johann Rehberger (Independent Researcher, Embrace The Red) Trust No AI: Prompt Injection Along The CIA Security Triad arxiv.org/abs/2412.06090
011