'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
2026-07-11T13:23:26Z•885cc72012b5930a43e535bc8a6c90834c278bc3120d0fe0ff78c7e9a5f445f7
AI-agentsDockerGiteaHelixInjectiveMFA-abuseRyuk-ransomware','legal-action'ShareFileU-BootXSSZimbraactive-exploitationauthentication-bypassbootloader-vulnerabilitiescode-review-automationcredible-threatcryptocurrency-theftfirmware-compromiseghostcommitnpm-malwarephishingprompt-injectionsecrets-exfiltrationsteganographyvishing
What happened
Multiple high-risk incidents and emerging threats were reported: researchers demonstrated ‘Ghostcommit’ steganographic prompt-injection in PNGs that can trick AI code-review agents and exfiltrate repo secrets; six U-Boot bootloader vulnerabilities could enable stealthy firmware compromise; attackers are actively exploiting a critical authentication-bypass in the official Gitea Docker image; Zimbra warned of a critical XSS in its Classic Web Client; an Injective SDK npm package was poisoned to steal crypto wallets; a new Helix group is using vishing, device-code phishing and MFA abuse to steal/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 885cc72012b5930a43e535bc8a6c90834c278bc3120d0fe0ff78c7e9a5f445f7
- Enrichment time
- 2026-07-11T13:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.