AI Agents Hijacked via Prompt Injection: Bug Bounties Paid, Security Advisories Withheld
Security researchers exploited prompt injection vulnerabilities in AI agents from Anthropic, Google, and Microsoft, stealing API keys through GitHub Actions integrations. All three companies paid bug bounties ranging from $100 to $1,337 but issued no CVEs or public advisories, leaving users on older versions exposed to potential attacks.