in the wild

Where it has already happened

One test decides what belongs here: the document a person reads and the document a machine reads are not the same document. This is the public record of that happening — incidents, research and vendor disclosures, dated and sourced. Each entry names the technique it used and links to the page for that technique, so the attack and the check for it sit side by side.

That covers two things people usually keep apart. Injection hides an instruction so a model acts on something the reader never saw. Evasionhides the incriminating part so a filter never notices, and the reader gets the message anyway. Same divergence, same techniques, and in the second case the person the divergence hurts is the one reading.

Only stories carried by a document belong here. A jailbreak typed into a chat box is not one, however widely it was reported, because there is no file and therefore nothing to check.

2026

29 Jul 2026 · The Register · research

Word worm crawls into Copilot, spreads chaos

A researcher showed that small white text in a Word document could tell Copilot to alter financial figures and copy the same instructions into every document it generated — a worm, disclosed after 144 days without a fix.

3 Mar 2026 · Unit 42, Palo Alto Networks · research

Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild

Twenty-two distinct payload techniques found on real malicious sites — zero font size, elements pushed 9,999 pixels off screen, display:none, attribute cloaking and prompts tucked inside SVG — aimed at everything from ad-review evasion to forced transactions. The SVG case reached us as `clean` until engine 0.263.0.

7 Jan 2026 · PromptArmor · vendor disclosure

Notion AI: Data Exfiltration

A résumé PDF carried an instruction in 1-point white-on-white text with a white image laid over it, and Notion AI built URLs containing salary expectations and candidate feedback, then embedded them as images so the browser sent them to the attacker.

2025

10 Jul 2025 · 0DIN · vendor disclosure

Phishing For Gemini

An email hid an instruction inside a zero-size white span, and Gemini's "summarise this email" obediently appended a fabricated Google security warning telling the reader to call an attacker's phone number.

next

Check your own file

Three commands: a key, credit, a verdict.

Start with the API