The attack relies on hidden prompts in a foreign language.
A flaw in Claude Code's GitHub Action let attackers bypass permission checks via fake bots and steal OIDC tokens through prompt injection.
SafeBreach researchers showed how hidden commands in Android notifications could trick Google Gemini through indirect prompt ...