logo

Turning AI Safeguards Into Weapons with HITL Dialog Forging

ID: 516a6a17-8fde-52eb-9cb4-0aef2e1fd29a

STIX ID: report--516a6a17-8fde-52eb-9cb4-0aef2e1fd29a

Feed Name: Checkmarx Zero

Threat Score
55/100

Date Published: 2025-12-16

Date Updated: 2026-04-27

Author: Ori Ron

...
...

This Checkmarx analysis describes the Lies-in-the-Loop (LITL) attack: an agent-targeting technique that forges Human-in-the-Loop (HITL) dialogs—via prompt and Markdown injection and content padding—to deceive users into approving malicious operations (including remote code execution) in code-assistant environments; the report documents PoCs against Claude Code and Copilot Chat, outlines attack variants and risks, recommends mitigations (sanitization, guardrails, UI clarity, sandboxing), and provides a disclosure timeline with vendor responses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.