A proof-of-concept attack hides prompt injection in a PNG file, turning routine code reviews into a path for secret theft.

A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and…

A new attack technique called GhostCommit just made AI-assisted code review look like a liability....