Turning AI Safeguards Into Weapons with HITL Dialog Forging
ID: 516a6a17-8fde-52eb-9cb4-0aef2e1fd29a
STIX ID: report--516a6a17-8fde-52eb-9cb4-0aef2e1fd29a
Feed Name: Checkmarx Zero
This Checkmarx analysis describes the Lies-in-the-Loop (LITL) attack: an agent-targeting technique that forges Human-in-the-Loop (HITL) dialogs—via prompt and Markdown injection and content padding—to deceive users into approving malicious operations (including remote code execution) in code-assistant environments; the report documents PoCs against Claude Code and Copilot Chat, outlines attack variants and risks, recommends mitigations (sanitization, guardrails, UI clarity, sandboxing), and provides a disclosure timeline with vendor responses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
