Everything in this lesson, sourced.
Every incident, CVE, and reference mentioned in LLM07:2025 — System Prompt Leakage — traced back to where it came from.
Framework License
This lesson is built on the OWASP Top 10 for Large Language Model Applications (2025), released under Creative Commons Attribution-ShareAlike 4.0. Definitions, vulnerability categories, mitigation structure, and attack scenarios are drawn directly from this framework. Real-world incidents and research are independent factual reporting, cited individually below.
CVE-2025-32711 — EchoLeak (Microsoft Copilot)CVSS 9.3
Microsoft Corporation · Aim Labs discovery · Zero-click prompt injection with context exfiltration via Markdown beacon
Cited for: Chained injection + leakage extraction type, EchoLeak scenario, access controls mitigation, slides 13, 24, 25
arXiv EchoLeak writeup →
Bing Chat “Sydney” System Prompt Extraction — February 2023Researcher Disclosure
Kevin Liu (Stanford University) · Disclosed publicly February 2023 · Corroborated by The Verge, Ars Technica
Cited for: Direct extraction technique, opening story, slide 1, slide 10, slides 20, 23, 25
Hacker News discussion →
GitHub Copilot Chat System Prompt Extraction — May 2023Researcher Disclosure
Multiple researchers · Documented on Hacker News May 2023 · Archived in public GitHub repositories
Cited for: Multi-step extraction technique, slides 11, 22, 23, 25
Hacker News →
EchoLeak — Zero-Click Prompt Injection in Microsoft 365 Copilot — January–May 2025Researcher Disclosure
Aim Labs · Responsibly disclosed to Microsoft January 2025 · Patched May 2025 · Published June 11, 2025
Cited for: Chained injection + leakage extraction type, CVE-2025-32711, slides 13, 24, 25
Full writeup →
Archived Leaked System Prompts — asgeirtj/system_prompts_leaksReference Archive
Community-maintained GitHub repository · Active 2025–2026 · Prompts from ChatGPT, Claude, Gemini, Copilot, Perplexity, Cursor, and others
Cited for: Mass prompt archiving reality, encoding extraction technique, slide 12
GitHub →
Stealing Copilot’s System Prompt — Zenity LabsSecurity Research
Zenity Labs · Detailed walkthrough of Copilot prompt extraction methodology
Cited for: Multi-step extraction technique, slide 11
Zenity Labs →
OWASP Top 10 for LLMs 2025 — Full PDFPrimary Framework
OWASP Foundation · v2025 PDF · CC BY-SA 4.0
Cited for: Full mitigation text, attack scenario definitions, overall lesson structure
PDF →