3 ms·
For bots in Slack, Discord, Teams, Telegram,... there is actually another exfiltration vector called "unfurling"! All an attacker has to do is render a hyperli
by wunderwuzzi23 2y ago
For bots in Slack, Discord, Teams, Telegram,... there is actually another exfiltration vector called "unfurling"!
All an attacker has to do is render a hyperlink, no clicking needed. I discussed this and how to mitigate it here: https://embracethered.com/blog/posts/2024/the-dangers-of-unfurling-and-what-you-can-do-about-it/ https://embracethered.com/blog/posts/2024/the-dangers-of-unf...
So, hopefully Slack AI does not automatically unfurl links...
- mosselman 2y agoDoesn’t the mitigation described only protects against unfurling, but still makes data leak if the user clicks the link themselves?
- wunderwuzzi23 2y agoCorrect. That's just focused on the zero click scenario of unfurling. The tricky part with a markdown link (as shown in the Slack AI POC) is that the actual URL is not directly visible in the UI. When rendering a full hyperlink in the UI a similar result can actually be achieved via ASCII Smuggling, where an attacker appends invisible Unicode tag characters to a hyperlink (some demos here: https://embracethered.com/blog/posts/2024/ascii-smuggling-and-hidden-prompt-instructions/ https://embracethered.com/blog/posts/2024/ascii-smuggling-an...) LLM Apps are also often vulnerable to zero-click image rendering and sometimes might also leak data via tool invocation (like browsing). I think the important part is to test LLM applications for these threats before release - it's concerning that so many organizations keep overlooking these novel vulnerabilities when adopting LLMs.
- deleted 2y ago[deleted]