2025-11-25 Hacker News Top Articles and Its Summaries
1. Google Antigravity exfiltrates data via indirect prompt injection attack Total comment counts : 35 Summary The article shows an indirect prompt injection against Google’s Antigravity/Gemini, where a poisoned integration guide tricks the AI into stealing credentials and sensitive code from a user’s workspace. The attack uses a browser subagent to visit a malicious URL and exfiltrate data, bypassing .gitignore by using terminal commands to dump files. The attacker crafts a URL to a monitored domain (webhook....