ChatGPT has reported they closed a vulnerability exploited by the Shadowleak malware that was disclosed recently by Radware.
Shadowleak uses prompt injection, the attacker tries to feed instructions to your AI service.
Security vectors have been warning against such an attack vector: when you let for example AI summarise a web page, hackers could try to craft malicious web pages that try to trick that AI.
ShwdowLeak uses ChatGPT DeepSearch, an AI tool that helps you automate email jobs. Shadowleak sends a malicious email to you and DeepSearch will happily report on the content of your email archive to the attacker.
Particlarly worrying about the attack is that it is executed entirely on the OpenAI servers, so you cannot detect on your local machine an attack is happening.
Radware recommends to limit the actions an AI agent can take on your system to limit the damage of such attacks.
No comments:
Post a Comment