Safeguard
Tag

prompt-injection

Safeguard articles tagged "prompt-injection" — guides, analysis, and best practices for software supply chain and application security.

100 articles

AI Security

MCP-Led Automation: Securing Model Context Protocol Workflows

MCP-led agent workflows hand real tools to a language model. That power is also the attack surface. Here is how tool poisoning works and how to defend against it.

May 19, 20267 min read
AI Security

EchoLeak (CVE-2025-32711): The First Zero-Click LLM Exfiltration in Production

Aim Security's CVE-2025-32711 exfiltrated Microsoft 365 Copilot data via a single crafted email. The XPIA classifier failed, CSP let attackers through, and CVSS 9.3 followed.

May 14, 20266 min read
AI Security

EchoLeak (CVE-2025-32711): The First Zero-Click Production LLM Exfiltration

A single crafted email could exfiltrate data from Microsoft 365 Copilot without a user click. We walk the attack chain, the patch, and the lessons for agent operators.

May 12, 20266 min read
AI Security

Prompt injection attacks against AI coding/security tools

AI coding assistants like Copilot and Cursor can be hijacked by hidden text in files, comments, and packages. Here's how prompt injection malware works and how Safeguard detects it.

May 9, 20266 min read
AI Security

What Is Prompt Engineering? A Security Guide for LLM Applications

Prompt engineering is how you steer an LLM, and it is also where a lot of application security now lives. Here is how to write prompts that resist injection and leakage.

May 8, 20266 min read
Regulatory Compliance

CISA's Agentic AI Secure Adoption Guide (May 2026): What It Means for Software Supply Chains

On May 4, 2026, CISA and international partners published guidance on the secure adoption of agentic AI. We break down the named risks, the recommended controls, and how to operationalize them for AppSec and platform teams.

May 6, 202611 min read
Agent Security

GitHub MCP Server Private-Repo Exfiltration: The May 2025 Invariant Labs Disclosure

Invariant Labs showed that a malicious GitHub Issue could hijack any MCP-connected agent into leaking private-repo contents. The architecture, not a bug, is the problem.

May 4, 20267 min read
AI Security

Jailbreak Meaning: What It Is in AI and Devices

Jailbreak has two meanings today: removing restrictions on a device, and tricking an AI model into ignoring its safety rules. This guide covers both.

Apr 22, 20265 min read
AI Security

What Is AI Jailbreaking? A Defender's Security Guide

To jailbreak AI means to bypass a model's safety guardrails with crafted prompts. Here is how the technique works and, more usefully, how to defend against it.

Apr 22, 20267 min read
AI Security

Line Jumping: How MCP Tool Descriptions Attack Before Tools Are Called

Trail of Bits coined 'line jumping' for prompt injection delivered through MCP tool descriptions on connection. It bypasses every tool-invocation guardrail by design.

Apr 21, 20266 min read
Frameworks

OWASP LLM Top 10 2025: System Prompt Leakage and Vector Weaknesses

The OWASP Top 10 for LLM Applications 2025 added System Prompt Leakage and Vector/Embedding Weaknesses, and elevated Sensitive Information Disclosure to #2. Here is the defender view.

Apr 19, 20267 min read
AI Security

MCP Security

MCP is standardizing how AI agents call tools, and attackers are already exploiting tool poisoning, rug pulls, and shadowing. Here's what MCP security actually requires.

Apr 17, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.