<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>AI Security Signals — VQV.me</title>
    <link>https://vqv.me/t/ai-security/</link>
    <description>Recent public signals for AI Security, refreshed every 4 hours.</description>
    <lastBuildDate>Thu, 18 Jun 2026 17:20:28 +0000</lastBuildDate>
    <atom:link xmlns:atom="http://www.w3.org/2005/Atom" href="https://vqv.me/t/ai-security/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CodeSentinel: Three-Layer Defense Against Indirect Prompt Injection in Code LLMs</title>
      <link>https://vqv.me/t/ai-security/#signal-d948d50f82</link>
      <guid>https://vqv.me/t/ai-security/#signal-d948d50f82</guid>
      <pubDate>Wed, 17 Jun 2026 16:12:50 +0000</pubDate>
      <description>CodeSentinel is a three-layer inference-time sanitizer designed to protect large language models from indirect prompt injection attacks hidden in code contexts such as comments, strings, and identifiers. It uses Tree-sitter to identify high-risk code syntax tree nodes and applies sanitization to pr... Why this is here: SOURCE-BACKED + 95 signal strength + source-backed + recent this week + low-noise result. Source: arXiv. Original: http://arxiv.org/abs/2606.19235v1</description>
      <category>SOURCE-BACKED</category>
    </item>
    <item>
      <title>AI Security Agent Tackles Multi-Vector Fraud and AML in Banking</title>
      <link>https://vqv.me/t/ai-security/#signal-1db27244be</link>
      <guid>https://vqv.me/t/ai-security/#signal-1db27244be</guid>
      <pubDate>Tue, 16 Jun 2026 05:58:40 +0000</pubDate>
      <description>Banks face both signature-based fraud and behavioral financial crimes, which require different detection methods. An AI security agent addresses these challenges by combining approaches to detect threats like card-not-present attacks and business email compromise. Why this is here: SOURCE-BACKED + 95 signal strength + source-backed + recent this week + low-noise result. Source: arXiv. Original: http://arxiv.org/abs/2606.17555v1</description>
      <category>SOURCE-BACKED</category>
    </item>
    <item>
      <title>Deep-XPIA: Prompt Injection Benchmark for Multi-Agent AI Systems</title>
      <link>https://vqv.me/t/ai-security/#signal-f3cd9301e6</link>
      <guid>https://vqv.me/t/ai-security/#signal-f3cd9301e6</guid>
      <pubDate>Tue, 16 Jun 2026 01:40:07 +0000</pubDate>
      <description>Deep-XPIA is a new benchmark designed to evaluate prompt injection vulnerabilities in multi-agent AI systems. It aims to help researchers identify and mitigate security risks in AI interactions. Why this is here: SOURCE-BACKED + 91 signal strength + recent this week + low-noise result. Source: Hacker News. Original: https://freyzo.github.io/deep-xpia/</description>
      <category>SOURCE-BACKED</category>
    </item>
    <item>
      <title>Risk-Aware Causal Gating Enhances LLM Agent Security via Tool Contract Integrity</title>
      <link>https://vqv.me/t/ai-security/#signal-f7c6055fc5</link>
      <guid>https://vqv.me/t/ai-security/#signal-f7c6055fc5</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:11 +0000</pubDate>
      <description>Risk-Aware Causal Gating (RACG) protects tool-augmented large language model (LLM) agents from indirect prompt injection by restricting access to dangerous tools. This approach shifts the trust requirement to the integrity of the tool contracts rather than the agent's compliance alone. Why this is here: SOURCE-BACKED + 95 signal strength + source-backed + recent this week + low-noise result. Source: arXiv. Original: http://arxiv.org/abs/2606.18550v1</description>
      <category>SOURCE-BACKED</category>
    </item>
    <item>
      <title>Security Challenges and Framework for Long-Horizon Agentic AI Systems</title>
      <link>https://vqv.me/t/ai-security/#signal-b51940d9f0</link>
      <guid>https://vqv.me/t/ai-security/#signal-b51940d9f0</guid>
      <pubDate>Fri, 12 Jun 2026 10:39:49 +0000</pubDate>
      <description>This paper analyzes security threats and evaluation methods for long-horizon agentic AI systems, proposing a taxonomy of threats and a framework for attack propagation analysis. It aims to guide future research in securing agentic AI. Why this is here: SOURCE-BACKED + 95 signal strength + source-backed + recent this week + low-noise result. Source: arXiv. Original: http://arxiv.org/abs/2606.14816v1</description>
      <category>SOURCE-BACKED</category>
    </item>
    <item>
      <title>Google Workspace’s continuous approach to mitigating indirect prompt injections</title>
      <link>https://vqv.me/t/ai-security/#signal-67002ac6ac</link>
      <guid>https://vqv.me/t/ai-security/#signal-67002ac6ac</guid>
      <pubDate>Thu, 02 Apr 2026 16:00:00 +0000</pubDate>
      <description>&lt;span class="byline-author"&gt;Posted by Adam Gavish, Google GenAI Security Team&lt;/span&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="docs-internal-guid-963e2379-7fff-2c42-f377-675bf409d663"&gt;&lt;p dir="ltr" style="line-height: 1.38; margin-bottom: 0pt; margin-top: 0pt;"&gt;&lt;span fac... Why this is here: SOURCE-BACKED + 95 signal strength + source-backed + low-noise result. Source: Google Security Blog. Original: http://security.googleblog.com/2026/04/google-workspaces-continuous-approach.html</description>
      <category>SOURCE-BACKED</category>
    </item>
    <item>
      <title>Mitigating prompt injection attacks with a layered defense strategy</title>
      <link>https://vqv.me/t/ai-security/#signal-44a7b60e8c</link>
      <guid>https://vqv.me/t/ai-security/#signal-44a7b60e8c</guid>
      <pubDate>Fri, 13 Jun 2025 16:03:00 +0000</pubDate>
      <description>&lt;span class="byline-author"&gt;Posted by Adam Gavish, Google GenAI Security Team&lt;/span&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="docs-internal-guid-673cf5ee-7fff-42cb-83fa-7f963bac5563"&gt;&lt;p dir="ltr" style="line-height: 1.38; margin-bottom: 0pt; margin-top: 0pt;"&gt;&lt;span fac... Why this is here: SOURCE-BACKED + 95 signal strength + source-backed + low-noise result. Source: Google Security Blog. Original: http://security.googleblog.com/2025/06/mitigating-prompt-injection-attacks.html</description>
      <category>SOURCE-BACKED</category>
    </item>
    <item>
      <title>Securing CI/CD in an agentic world: Claude Code Github action case</title>
      <link>https://vqv.me/t/ai-security/#signal-7d19fede70</link>
      <guid>https://vqv.me/t/ai-security/#signal-7d19fede70</guid>
      <pubDate>Fri, 05 Jun 2026 16:46:47 +0000</pubDate>
      <description>&lt;p&gt;Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack chain, responsible disclosure process, Anthropic's mitigat... Why this is here: SOURCE-BACKED + 95 signal strength + source-backed + low-noise result. Source: Microsoft Security Blog. Original: https://www.microsoft.com/en-us/security/blog/2026/06/05/securing-ci-cd-in-agentic-world-claude-code-github-action-case/</description>
      <category>SOURCE-BACKED</category>
    </item>
    <item>
      <title>An AI Security Agent for University ACMIS: Multi-Vector Threat Detection and Automated Response</title>
      <link>https://vqv.me/t/ai-security/#signal-3fd059861b</link>
      <guid>https://vqv.me/t/ai-security/#signal-3fd059861b</guid>
      <pubDate>Sat, 06 Jun 2026 17:33:31 +0000</pubDate>
      <description>University Academic Management Information Systems (ACMIS) are high-value targets for a wide spectrum of security threats including brute-force login attacks, payment fraud, privilege escalation, insider data theft, and academic integrity violations. Traditio... Why this is here: SOURCE-BACKED + 95 signal strength + source-backed + low-noise result. Source: arXiv. Original: http://arxiv.org/abs/2606.08270v2</description>
      <category>SOURCE-BACKED</category>
    </item>
    <item>
      <title>The catalogue of prompt injection attacks</title>
      <link>https://vqv.me/t/ai-security/#signal-1e4e374605</link>
      <guid>https://vqv.me/t/ai-security/#signal-1e4e374605</guid>
      <pubDate>Mon, 15 Jun 2026 14:00:58 +0000</pubDate>
      <description>Hacker News discussion with 8 points and 3 comments. Why this is here: SOURCE-BACKED + high signal strength + recent this week + low-noise result. Source: Hacker News. Original: https://archestra.ai/blog/10-basic-prompt-injections</description>
      <category>SOURCE-BACKED</category>
    </item>
    <item>
      <title>Safeguarding VS Code against prompt injections</title>
      <link>https://vqv.me/t/ai-security/#signal-d1d8d0e622</link>
      <guid>https://vqv.me/t/ai-security/#signal-d1d8d0e622</guid>
      <pubDate>Mon, 25 Aug 2025 16:01:12 +0000</pubDate>
      <description>&lt;p&gt;When a chat conversation is poisoned by indirect prompt injection, it can result in the exposure of GitHub tokens, confidential files, or even the execution of arbitrary code without the user's explicit consent. In this blog post, we'll explain which VS Co... Why this is here: SOURCE-BACKED + 93 signal strength + source-backed + low-noise result. Source: GitHub Security Lab. Original: https://github.blog/security/vulnerability-research/safeguarding-vs-code-against-prompt-injections/</description>
      <category>SOURCE-BACKED</category>
    </item>
    <item>
      <title>AI threats in the wild: The current state of prompt injections on the web</title>
      <link>https://vqv.me/t/ai-security/#signal-3e2a7472c3</link>
      <guid>https://vqv.me/t/ai-security/#signal-3e2a7472c3</guid>
      <pubDate>Thu, 23 Apr 2026 21:38:00 +0000</pubDate>
      <description>&lt;span class="byline-author"&gt;Posted by Thomas Brunner, Yu-Han Liu, Moni Pande&lt;/span&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="docs-internal-guid-49e83394-7fff-3df2-a974-c7291d12beb8"&gt;&lt;p dir="ltr" style="line-height: 1.38; margin-bottom: 10pt; margin-top: 0pt;"&gt;&lt;span fac... Why this is here: SOURCE-BACKED + 91 signal strength + source-backed + low-noise result. Source: Google Security Blog. Original: http://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html</description>
      <category>SOURCE-BACKED</category>
    </item>
  </channel>
</rss>
