Episode

Ghosted by Grafana

Podcast
Research Saturday
Published
May 23, 2026
Duration seconds
1558
Processing state
not_requested
Canonical source
https://thecyberwire.com/podcasts/research-saturday/426/notes
Audio
https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW7966216911.mp3
JSON
/v1/public/podcasts/research-saturday-1377435/episodes/ghosted-by-grafana
Markdown
/podcast/research-saturday-1377435/ghosted-by-grafana.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/ghosted-by-grafana/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/research-saturday-1377435/ghosted-by-grafana.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Today we are joined by ⁠Sasi Levi⁠, Security Research Lead at ⁠Noma Security⁠, sharing their team's work on "GrafanaGhost: The Phantom Stealing Your Data." Researchers at Noma Security disclosed “GrafanaGhost,” a vulnerability that could allow attackers to silently exfiltrate sensitive business data from Grafana dashboards using indirect prompt injection techniques. The attack chains together multiple bypasses, including protocol-relative URLs and AI guardrail manipulation, to trick Grafana into sending sensitive data to attacker-controlled servers without requiring user interaction. Researchers say the flaw highlights growing risks tied to AI-integrated enterprise platforms, where attackers increasingly target AI behavior and weak security controls instead of traditional software bugs. The research and executive brief can be found here: ⁠GrafanaGhost: The Phantom Stealing Your Data⁠