New 'Cryptographic Context Injection' Attack Could Exfiltrate Grok User Data via Malicious Web Pages
Adversa AI discloses a novel technique that may allow attackers to steal conversation context and user metadata from xAI's Grok chatbot.

Key Takeaways
- Adversa AI disclosed a new attack technique called 'Cryptographic Context Injection' targeting xAI's Grok chatbot.
- The attack could cause Grok to leak user name, approximate location, subscription tier, and conversation prompts to an attacker-controlled server.
- The attack is triggered when a user asks Grok to summarize a malicious web page.
Related Security News

JadePuffer Agentic AI Attacks Target Azure Tenants, Destroy Cloud Resources
Security researchers have observed the JadePuffer ransomware operator conducting agent-driven attacks against Azure cloud tenants. The attacks involve reconnaissance, credential theft, and the destruction of core cloud components. Details regarding the specific use of agentic AI remain reported but unconfirmed.

Carbonato Botnet Leverages Hermes Agent AI Framework to Compromise Docker Hosts
Security researchers have identified a new botnet campaign, tracked as Carbonato, that repurposes the open-source Hermes Agent AI framework to compromise Docker hosts. The malware leverages exposed container endpoints to execute arbitrary commands through Telegram integration and harvests AI API keys and other sensitive credentials stored on compromised systems.



