TGViewer
SITREP - Independent OSINT Channel SITREP - Independent OSINT Channel @sitreports · 23K subscribers
Post #39536 198
🤖 GitHub Copilot CLI prompt chain can exfiltrate local secrets

Adversa AI disclosed a Cryptographic Context Injection technique against GitHub Copilot CLI in autopilot mode. In the demonstrated chain, an attacker-controlled webpage fed encrypted instructions, pushed the agent to read local files while building a fake decryption key, then triggered a second request that sent the collected data off-host. Researchers reported a .env.prod file was exfiltrated in 28 seconds.

The key issue is trust at runtime: plaintext revealed after decryption was treated as valid context even when equivalent visible instructions were refused. GitHub reportedly validated the behavior but did not classify it as a vulnerability.

🛰️ Open sources - closed narratives
@sitreports
More from @sitreports
  1. Oct 8, 2026🔍 SonicWall patches CVSS 10 pre-auth flaw in SMA1000 SonicWall has issued hotfixes for fo…
  2. Oct 8, 2026🤖 Pentagon starts AI pilot for classification control The Pentagon will begin a small-sca…
  3. Oct 8, 2026🔍 Eight npm packages used to push Overlord RAT and stealer Eight malicious npm packages w…
  4. Oct 8, 2026📝You reap what you sow📝 Ukrainians lose South Korean ambassador The Kryvyi Rih school of…
  5. Oct 8, 2026🤖 PoeLLM Malware Expands Cryptojacking Footprint PoeLLM has reportedly infected more than…
  6. Oct 8, 2026🤖 Progress DataDirect agent flaw enables OS command execution Progress disclosed CVE-2026…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →