Hidden prompt injection is showing up in "Ask AI" buttons on marketing pages
August 11, 2026. From issue 1 of The Compliance Brief, 3 stories for teams running an ISO 27001 or ISO 42001 management system.
Issue 1 of The Compliance Brief went to subscribers on August 11, 2026. 3 of its 5 stories bear on ISO 27001, ISO 42001 and supplier risk, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for teams running an ISO 27001 or ISO 42001 management system.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: The Hacker News
Researchers observed production websites embedding hidden prompt injection payloads inside pre-filled deep links behind "Ask AI" buttons, including on marketing and competitor comparison pages. The technique needs no malware, no stolen credentials and no zero-day, because it abuses a normal feature of major AI assistants.
Our take, in short
This one sits on your marketing site rather than in your product, which means the people shipping it do not report to your head of engineering. If you have added an AI assistant handoff to your site, someone should be reviewing what those links actually carry and where the text comes from.
Read the full take on traztech.ca
LexisNexis pulled products offline over a third-party vendor incident
Source: BleepingComputer
LexisNexis took several services offline, including Diligence and the Metabase API, in response to unusual activity on servers hosted and managed by a third-party vendor it has not named. The company treated the shutdown as part of its incident response.
Our take, in short
Taking the service down was the right call, and it is also the version of vendor risk that most SaaS companies have never modelled. Your subprocessor list probably names the screening or data provider, and almost certainly says nothing about who runs their infrastructure, so an outage two layers out becomes your degraded onboarding flow and your customer notification.
Read the full take on traztech.ca
Gunra ransomware is getting in through firewalls, per a joint advisory
Source: The Hacker News
US and South Korean agencies issued a joint advisory on Gunra, a ransomware-as-a-service operation that has been breaching organizations by exploiting vulnerabilities in Fortinet and Schneider Electric products. Named targets span critical infrastructure, healthcare, financial services and government.
Our take, in short
Nothing in this advisory is novel, which is the uncomfortable part. Internet-facing appliances remain the cheapest way in, and most companies I test have a documented patch SLA for servers and an informal one for the firewall and the VPN concentrator.
Read the full take on traztech.ca
Related on ISO27K
- Who needs ISO 42001, and who should wait
- ISO 27001 major and minor nonconformities
- ISO 27017 and ISO 27018 for cloud services
- Free ISO 27001 and ISO 42001 tools
Also in issue 1
Outside ISO 27001, ISO 42001 and supplier risk, but in the same email:
- New York fined a money transmitter for a weak program, not a breach
- The Snowflake extortion case ends with a guilty plea in Kitchener
All issues on ISO27K Newer: issue 2
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.