About
What this is
The Injection tracks AI security: prompt injection, jailbreaks, agent permissions and sandboxes, the supply chain of skills, MCP servers and plugins, and what labs claim about the safety of their models. Each item says what happened, how it works, who is exposed and what to do.
The rules
- Every link is fetched. If a source cannot be opened and read, the item does not go in.
- Researchers are credited by name. The people who did the work come first, not whoever reposted it.
- No padding. A quiet day is a short feed.
- Plain English. Written for defenders who are busy, not for a review panel.
Severity
- CRIT
- Exploited in the wild, or easy remote code execution or data theft in a widely used product with no fix. Act today.
- HIGH
- A working attack on a widely used AI product or ecosystem. A fix may exist. Patch or mitigate this week.
- MED
- Real and reproducible, but needs unusual setup, user help or a narrow audience. Plan a fix.
- LOW
- Minor, hard to exploit or mostly theoretical. Good to know.
- INFO
- Research, tools, evals or lab claims with no direct exposure. Context, not an alert.
How it updates
An agent runs every six hours. It reads vendor advisories, research groups, papers and community sources, writes a draft, and a script fetches every link in it before anything is published. The site is static: each update is a commit, and each commit redeploys.