Нотатки: реальні кейси

Робочі нотатки дослідження з посиланнями.

Prompt injection via LinkedIn content and AI-recruiter attacks: incident catalog, 2023-2026

Research date: 2026-10-01. Scope: documented real-world cases and lab demonstrations of prompt injection delivered through LinkedIn profiles, bios, job postings, messages, plus AI-recruiter attacks. Every entry has a verifiable source URL. Items that could not be confirmed are marked UNVERIFIED or listed under Gaps.

Key question 1: Zenity Labs demonstrations involving LinkedIn AI agents (2025)

Takeaway

Could not verify any Zenity Labs publication specifically about LinkedIn AI agents. Zenity Labs' own research index (zenity.io/labs, checked 2026-10-01) lists no LinkedIn-specific post, and searches surfaced no primary writeup. Treat the "Zenity phished an AI agent via LinkedIn" story as UNVERIFIED.

Cited Findings

Inferences

Gaps

Key question 2: Candidates hiding prompt injections in resumes and profiles to manipulate AI screeners or recruiters' LLMs

Takeaway

Three verified real-world LinkedIn cases exist (2023 anti-recruiter bio injection; 2026 LLM-recruiter caught red-handed; 2026 "My Lord" bio injection), plus a documented wave of white-text resume injections with hard prevalence data from Greenhouse and ManpowerGroup (2025).

Cited Findings

Inferences

Gaps

Key question 3: Job postings or recruiter messages carrying prompts targeting job seekers' AI assistants

Takeaway

One verified, reverse-direction pattern exists: employers hiding prompts inside job postings to flag AI-generated applications (defense use of the same technique). No verified incident of a job posting attacking a job seeker's AI assistant was found.

Cited Findings

Inferences

Gaps

Key question 4: LinkedIn DMs or posts used against AI agents (browsing agents reading LinkedIn pages)

Takeaway

No verified incident found of LinkedIn DMs or posts compromising a general-purpose browsing/AI agent product. The verified LinkedIn-content attacks (Key question 2) hit recruiter-side LLM pipelines, not browser agents.

Cited Findings

Inferences

Gaps

Key question 5: Vendor bug bounty or disclosed vulnerabilities in LinkedIn AI features

Takeaway

Nothing verified. No public disclosure, CVE, or bug-bounty writeup for LinkedIn Hiring Assistant or LinkedIn AI-assisted messaging was found.

Cited Findings

Inferences

Gaps

Key question 6: Prevalence scans (how common such payloads are on LinkedIn or in job ads)

Takeaway

Resume-side prevalence is quantified (Greenhouse: 1 percent of 300M scanned resumes H1 2025 contained white-text messages; ManpowerGroup: about 10 percent of AI-scanned resumes, roughly 100,000 per year, contain hidden text; self-report 41 percent). No scan quantifying payloads inside LinkedIn descriptions or job ads was verified.

Cited Findings

Inferences

Gaps

Method and limitations

← До змісту дослідження