ainewsblitz.com

Breaking

'Ghostcommit' Buries Prompt Injection in Images to Fool AI Code Reviewers and Steal Secrets

  • Security
  • AI Agents
  • Software Dev & Coding

A newly disclosed proof-of-concept dubbed "Ghostcommit" hides prompt injection inside images to trick AI code reviewers and coding agents into leaking a repository's secrets (its .env file). Reported by BleepingComputer on July 11, 2026, the technique was developed by Sudipta Chattopadhyay and colleagues at the ASSET Research Group at the University of Missouri-Kansas City, who published full details and proof-of-concept code.

Continue reading

The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.

$20
Read this article
$29/month
Unlimited — all 7,843 articles, the full archive, and comprehension quizzes
Save 72%
$98/year
≈ $8.17/month
Unlimited, billed once a year