A newly disclosed proof-of-concept dubbed "Ghostcommit" hides prompt injection inside images to trick AI code reviewers and coding agents into leaking a repository's secrets (its .env file). Reported by BleepingComputer on July 11, 2026, the technique was developed by Sudipta Chattopadhyay and colleagues at the ASSET Research Group at the University of Missouri-Kansas City, who published full details and proof-of-concept code.
Continue reading
The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in✓ Signed in — this article isn’t included in your current plan.