Mastodon Feed: Post

Mastodon Feed

Boosted by glyph ("Glyph"):
mttaggart@infosec.exchange ("Taggart :ifin:") wrote:

Indirect prompt injection attacks are really in their infancy. As we enable more agents and more tools/integrations, the possibilities for this fundamentally unfixable vulnerability get scarier.

Imagine giving all your secrets to an assistant and expecting them to get phished. That's what this is.

https://www.bleepingcomputer.com/news/security/new-attack-turned-microsoft-365-copilot-into-1-click-data-theft-tool/