The latest in Playbook
A backdoored Nx Console extension gave attackers a foothold inside GitHub on May 19. Worm-style spread, CI/CD credentials, 11-minute detection window. The boring hygiene fixes every Copilot/Cursor team owes itself.
White-text payloads, zero-pixel fonts, alt-text smuggling, Unicode tag characters, malicious font mappings. A field guide to indirect prompt injection mechanics with 2026 research and real attack patterns.
Yes, comprehensive policies reviewed annually
Partial - some policies exist but incomplete
In draft - working on documenting policies
No documented security policies