# Prompt injection attacks surge 340% YoY; CVE-2025-53773 exploits GitHub Copilot and Cursor

> Prompt injection has graduated from a clever party trick to the most pressing security problem in AI. Security firm Cycode reports the attacks jumped 340% year over year, and OWASP now ranks prompt injection as LLM01, its top risk for large language model applications, citing success rates between 50 and 84%. The uncomfortable part is that there is no complete fix: models from OpenAI, Google, and Anthropic all remain vulnerable by design. The stakes get concrete in the tooling developers actually use. Critical vulnerabilities were disclosed in Microsoft Copilot, GitHub Copilot, and Cursor, and one flaw, CVE-2025-53773, let attackers hide instructions inside a pull request to achieve remote code execution. In other words, an AI coding assistant reading a poisoned file could be tricked into running an attacker's commands. As companies wire language models into email, codebases, and internal systems, every untrusted piece of text becomes a potential command channel. Defenses are improving, but for now the honest guidance is to assume any AI agent with real permissions can be talked into misusing them.

_Section: [Daily AI Updates](https://www.wortins.com/daily-ai) · Source: Cycode · Published Friday, August 7, 2026_

## Wortins' read

Prompt injection has graduated from a clever party trick to the most pressing security problem in AI. Security firm Cycode reports the attacks jumped 340% year over year, and OWASP now ranks prompt injection as LLM01, its top risk for large language model applications, citing success rates between 50 and 84%. The uncomfortable part is that there is no complete fix: models from OpenAI, Google, and Anthropic all remain vulnerable by design. The stakes get concrete in the tooling developers actually use. Critical vulnerabilities were disclosed in Microsoft Copilot, GitHub Copilot, and Cursor, and one flaw, CVE-2025-53773, let attackers hide instructions inside a pull request to achieve remote code execution. In other words, an AI coding assistant reading a poisoned file could be tricked into running an attacker's commands. As companies wire language models into email, codebases, and internal systems, every untrusted piece of text becomes a potential command channel. Defenses are improving, but for now the honest guidance is to assume any AI agent with real permissions can be talked into misusing them.

## Source

[Read the full story at Cycode](https://cycode.com/blog/ai-security-vulnerabilities/)

## Related coverage

- [Callosum Raises $100 Million to Match AI Tasks with Most Cost-Effective Models](https://www.wortins.com/story/callosum-raises-100-million-to-match-ai-tasks-with-most-cost-da05cef6) — [Bloomberg](https://www.bloomberg.com/news/articles/2026-08-20/ai-startup-callosum-raises-100-million-to-make-ai-tasks-cheaper)
- [Nvidia Agrees to Acquire Hugging Face for $13 Billion](https://www.wortins.com/story/nvidia-agrees-to-acquire-hugging-face-for-13-billion-17f12bb8) — [TechCrunch](https://techcrunch.com/2026/08/26/nvidia-closes-in-on-hugging-face-acquisition/)
- [Cohere Launches Command A+ Mixture-of-Experts Model](https://www.wortins.com/story/cohere-launches-command-a-mixture-of-experts-model-5d840970) — [Cohere](https://docs.cohere.com/docs/command-a-plus)
- [Anthropic Adds Claude Mythos 5 to Claude Security for Vulnerability Scanning](https://www.wortins.com/story/anthropic-adds-claude-mythos-5-to-claude-security-for-vulner-34ff7302) — [Anthropic](https://claude.com/blog/bringing-claude-mythos-5-to-more-defenders)
- [Chinese AI Models Now 60% of OpenRouter Traffic, Surpassing US Market Share](https://www.wortins.com/story/chinese-ai-models-now-60-of-openrouter-traffic-surpassing-us-ff49998d) — [Fortune](https://fortune.com/2026/08/21/what-is-ai-death-zone-china-models-open-source/)
- [DARPA and US Air Force Successfully Fly F-16 Fighter Jet Under Full AI Control](https://www.wortins.com/story/darpa-and-us-air-force-successfully-fly-f-16-fighter-jet-und-b659da37) — [DARPA](https://www.darpa.mil/news/2026/darpa-us-air-force-fly-ai-controlled-f-16)

---

_Curated and written by [Wortins](https://www.wortins.com) — The daily AI briefing. Every story links to its original source; the "Wortins read" on each is our own original analysis. [About Wortins & our editorial approach](https://www.wortins.com/about)._
