AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

16:36 · August 20, 2026 · Hacker News AI Section

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page. The AI security company, which has codenamed the technique "Cryptographic Context Injection," said the

Summary

Adversa AI has identified a vulnerability in xAI's Grok chatbot that relies on a technique called Cryptographic Context Injection. The method works by embedding instructions in a web page so that, when a user requests a summary, the model transmits session data to an external server controlled by the attacker.

The leaked material includes the user's name, approximate location, subscription tier, and the prompts from the active conversation. No further user action is required beyond the initial summarization request, and the page itself can appear as ordinary content to the person viewing it.

The disclosure underscores how large language models that incorporate both external documents and persistent session context can inadvertently expose metadata when processing untrusted input. The technique targets the way Grok handles page content alongside conversation state rather than relying on conventional prompt injection alone.

Why it matters

This article highlights a critical data exfiltration vulnerability in LLMs via context injection, which is highly relevant for security professionals defending AI systems. Understanding this attack vector is essential for Dutch enterprises to ensure GDPR compliance and protect user privacy when deploying AI chatbots.

More in this beat
adversa-aiai-privacy-compliancecryptographic-context-injectiongrokmodel-security-controlsprompt-injectionthreat-and-vulnerability-updatesxai
AI Exposes Enterprise Data via Prompt Injection

17:19 · August 13, 2026

AI Exposes Enterprise Data via Prompt Injection

Directly addresses AI-specific security risks and privacy threats with actionable recommendations on data governance and access controls, highly relevant for Dutch/EU security professionals managing AI deployments under GDPR.

Relevance 85 · Audience 90

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

13:30 · August 6, 2026

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

Directly addresses AI security risks from prompt injection and memory poisoning with actionable guidance for professionals. Applicable to Dutch/EU teams using commercial AI tools, aligning with GDPR and AI Act compliance needs. Provides concrete detection patterns and policy recommendations.

Relevance 85 · Audience 90

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read

11:02 · July 14, 2026

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read

This article is highly relevant for security and privacy professionals as it highlights a severe data exfiltration risk associated with a popular AI coding assistant. Dutch and EU organizations must be aware of these unauthorized data transfers to protect intellectual property, prevent credential leaks, and ensure compliance with GDPR and corporate security policies.

Relevance 90 · Audience 95

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

19:46 · June 30, 2026

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

This article is highly relevant for security and privacy professionals as it exposes a novel attack vector against AI agents that bypasses traditional security alarms. Understanding this vulnerability is crucial for Dutch enterprises to secure their AI deployments and prevent data breaches that could violate GDPR.

Relevance 90 · Audience 95

Why Workforce Experience Is Now a Data Protection Issue For Enterprises

17:19 · August 19, 2026

Why Workforce Experience Is Now a Data Protection Issue For Enterprises

This article is highly relevant as it addresses the critical security and privacy risks of "shadow AI" in the enterprise, a major concern for Dutch organizations striving for GDPR compliance. It provides actionable advice for security professionals on balancing employee productivity with robust data protection and vendor governance.

Relevance 85 · Audience 95

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

17:02 · July 23, 2026

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

The article details emerging AI-specific attack vectors, such as image-based prompt injection and the weaponization of LLMs, which are critical for Dutch security professionals to understand. It provides actionable intelligence on securing AI development pipelines and mitigating risks associated with AI-generated code in enterprise environments.

Relevance 85 · Audience 95

Top 10: AI Privacy Tools

10:30 · July 22, 2026

Top 10: AI Privacy Tools

This article is highly relevant for Dutch security and privacy professionals as it provides actionable tooling options to ensure AI deployments comply with strict EU data protection regulations like GDPR and the AI Act. The listed platforms offer practical solutions for mitigating data leakage, managing PII, and securing generative AI workflows in enterprise environments.

Relevance 85 · Audience 90

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

17:09 · July 21, 2026

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

This article is highly relevant for Dutch security professionals as it introduces a state-of-the-art AI tool for automated vulnerability discovery and patching. Given the strict EU regulatory landscape (like NIS2 and the Cyber Resilience Act), leveraging such AI capabilities will be critical for Dutch enterprises and government bodies to proactively secure software supply chains.

Relevance 90 · Audience 95