Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kerng
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
GitHub Copilot: From Prompt Injection to Data Exfiltration
(embracethered.com)
7 points
by
kerng
2y ago
|
0 comments
32.
▲
Automatic Tool Invocation When Browsing with ChatGPT – Threats and Mitigations
(embracethered.com)
4 points
by
kerng
2y ago
|
0 comments
33.
▲
Bobby Tables but with LLMs – Google NotebookML Data Exfiltration
(embracethered.com)
3 points
by
kerng
2y ago
|
0 comments
34.
▲
by
kerng
3y ago
Yeah, wondering how the initial test account got compromised. Probably no MFA and password spray via OAuth ROPC flow, then lateral movement. M365 is quite bad at enforcing MFA, it's pay to play.
35.
▲
by
kerng
3y ago
Might be better to say that most companies think they have that kind of isolation, but pentesting, red teaming and incidents then later proof they don't. I have even seen companies routing prod traffic to test systems, it's not un
36.
▲
ASCII Smuggler: Crafting and Decoding Invisible Text Using Unicode Tags
(embracethered.com)
6 points
by
kerng
3y ago
|
1 comments
37.
▲
Prompt Injection exploit in Google Bard leads to data exfiltration
(twitter.com)
5 points
by
kerng
3y ago
|
0 comments
38.
▲
Analyze an image with ChatGPT and have your chat history stolen
(twitter.com)
3 points
by
kerng
3y ago
|
0 comments
39.
▲
ChatGPT Browsing Prompt Injection to Chat History Exfiltration
(twitter.com)
3 points
by
kerng
3y ago
|
0 comments
40.
▲
With AI, Hackers Can Simply Talk Computers into Misbehaving
(wsj.com)
1 points
by
kerng
3y ago
|
1 comments
41.
▲
Image Based Prompt Injections (Bard and Bing Chat)
(twitter.com)
4 points
by
kerng
3y ago
|
0 comments
42.
▲
Google Bard: Image to Prompt Injection
(twitter.com)
24 points
by
kerng
3y ago
|
2 comments
43.
▲
Google Docs AI Features: Vulnerabilities and Risks
(embracethered.com)
4 points
by
kerng
3y ago
|
0 comments
44.
▲
OpenAI Removes the “Chat with Code” Plugin from Store
(embracethered.com)
6 points
by
kerng
3y ago
|
0 comments
45.
▲
ChatGPT Plugins: Visit a website and have your company's source code stolen
(twitter.com)
3 points
by
kerng
3y ago
|
0 comments
46.
▲
Plugin Vulnerabilities: Visit a Website and Have Your Source Code Stolen
(embracethered.com)
6 points
by
kerng
3y ago
|
0 comments
47.
▲
Bing Chat Data Exfiltration Exploit Explained (Was Fixed by Microsoft)
(embracethered.com)
8 points
by
kerng
3y ago
|
0 comments
48.
▲
by
kerng
3y ago
This makes me wonder why does OpenAI not build in a mitigation by default that requires a confirmation that they control? Why leave it up to the tool developers to mitigate, many of whom never heard of confused deputy attacks? Seems like a
49.
▲
ChatGPT: Indirect Prompt Injection to WarGames
(twitter.com)
1 points
by
kerng
3y ago
|
0 comments
50.
▲
ChatGPT Plugin Exploit Details: From Prompt Injection to Accessing Private Data
(embracethered.com)
5 points
by
kerng
3y ago
|
0 comments
51.
▲
by
kerng
3y ago
Are these all vulnerable to Indirect Prompt Injections or is there a solution to this rising security challenge? Anything plugin developers should do to limit impact?
52.
▲
ChatGPT Plugins: Indirect prompt injection leading to data exfiltration (POC)
(youtube.com)
11 points
by
kerng
3y ago
|
0 comments
53.
▲
ChatGPT Plugins: Data Exfiltration via Images and Cross Plugin Request Forgery
(embracethered.com)
3 points
by
kerng
3y ago
|
0 comments
54.
▲
ChatGPT: Indirect Prompt Injection via YouTube Transcripts
(embracethered.com)
13 points
by
kerng
3y ago
|
0 comments
55.
▲
by
kerng
3y ago
Indirect Prompt Injection via YouTube transcripts https://embracethered.com/blog/posts/2023/chatgpt-plugin-you...
56.
▲
AI Injections: Direct and Indirect Prompt Injections and Their Implications
(embracethered.com)
1 points
by
kerng
3y ago
|
0 comments
57.
▲
by
kerng
3y ago
These attacks are more closely related to social engineering the LLM, rather then traditional "injections". https://embracethered.com/blog/posts/2023/ai-injections-dire... There aren't any spec
58.
▲
by
kerng
4y ago
I was a bit underwhelmed by the depth of the conversation - it entirely lacked an opposing or at least an alternate view to try to understand the other side. Going in I thought Andrew would moderate it like that, but it was more of a bubble
59.
▲
by
kerng
4y ago
Very interesting thought on how to mitigate this, because I think a solution like with parameterized queries isnt possible - at least with my current understanding (the attack is more of a "social engineering" attack on the AI). R
60.
▲
Direct and Indirect AI Injections and Their Implications
(embracethered.com)
2 points
by
kerng
4y ago
|
2 comments
More ›