‘GrafanaGhost’ bypasses Grafana’s AI defenses without leaving a trace

2026-04-07T14:51:42Z840aaa1cf8b7bc1bac98b93daf48e7a83678f18516de06ab1a8bc0716dce47d3
AI prompt injectionAkiraCVE-2026-35616FortiClient EMSFortinetGrafanaGrafanaGhostHandalaICEParagonStrykerTA416actively exploitedcyberespionagedata exfiltrationdecryptorhotfixpcTattleTale prosecution","CISA funding cuts","US cyber policy"prompt injectionransomwarerapid encryptionspywarestalkerwarewiperzero-day

What happened

CyberScoop roundup: Noma Security disclosed “GrafanaGhost,” an indirect prompt‑injection technique that leverages Grafana’s built‑in AI to exfiltrate sensitive data without obvious traces. Fortinet customers face an actively exploited FortiClient EMS zero‑day (CVE‑2026‑35616) with a hotfix recommended while a full patch is pending. Threat intelligence highlights include Akira ransomware achieving initial access-to‑encryption in under an hour (and producing working decryptors), an Iranian‑linked Handala wiper strike against medtech firm Stryker, and a resurgence of TA416 cyberespionage inEurope

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
840aaa1cf8b7bc1bac98b93daf48e7a83678f18516de06ab1a8bc0716dce47d3
Enrichment time
2026-04-07T14:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.