Prompt Injection Flaw in GitHub Actions Hits Fortune 500 Firms
ID: 6dda2df2-30f2-539a-8a61-1ebd7d930456
STIX ID: report--6dda2df2-30f2-539a-8a61-1ebd7d930456
Feed Name: cybersecurityNews.com
Threat Score
Aikido Security disclosed a new prompt-injection vulnerability pattern dubbed “PromptPwnd” that affects AI-integrated CI/CD workflows (e.g., GitHub Actions, GitLab) using agents like Google’s Gemini CLI, Claude Code, and OpenAI Codex; researchers demonstrated a PoC where malicious GitHub issue content caused an AI agent to execute privileged actions and expose API keys, with at least five Fortune 500 companies confirmed impacted and vendor fixes and detection rules provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
