GitHub의 AI 에이전트에서 비공식 데이터 유출 취약점 발견.
GitLost라는 프롬프트 인젝션 공격이 Noma Security에 의해 발견되었습니다. 이 공격은 GitHub의 새로운 에이전틱 워크플로우를 이용하여 비공식 데이터 누출을 유도합니다. 공격자는 공개 GitHub 이슈에 숨겨진 지침을 삽입하여 보안 장치를 우회하고 AI 에이전트로 하여금 기밀 정보를 공개 코멘트에 드러내도록 할 수 있습니다.
GitLost exploits GitHub's AI agent to leak private data.
The GitLost prompt injection exploit was discovered by Noma Security. This exploit tricks GitHub's new Agentic Workflows into leaking private data. Attackers can embed concealed instructions within public GitHub issues to circumvent security safeguards and induce AI agents to reveal confidential information in public comments.