'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets

2026-07-11T13:23:26Z885cc72012b5930a43e535bc8a6c90834c278bc3120d0fe0ff78c7e9a5f445f7
AI-agentsDockerGiteaHelixInjectiveMFA-abuseRyuk-ransomware','legal-action'ShareFileU-BootXSSZimbraactive-exploitationauthentication-bypassbootloader-vulnerabilitiescode-review-automationcredible-threatcryptocurrency-theftfirmware-compromiseghostcommitnpm-malwarephishingprompt-injectionsecrets-exfiltrationsteganographyvishing

What happened

Multiple high-risk incidents and emerging threats were reported: researchers demonstrated ‘Ghostcommit’ steganographic prompt-injection in PNGs that can trick AI code-review agents and exfiltrate repo secrets; six U-Boot bootloader vulnerabilities could enable stealthy firmware compromise; attackers are actively exploiting a critical authentication-bypass in the official Gitea Docker image; Zimbra warned of a critical XSS in its Classic Web Client; an Injective SDK npm package was poisoned to steal crypto wallets; a new Helix group is using vishing, device-code phishing and MFA abuse to steal/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
885cc72012b5930a43e535bc8a6c90834c278bc3120d0fe0ff78c7e9a5f445f7
Enrichment time
2026-07-11T13:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.