მკვლევარების თქმით, Grok-ი მომხმარებელთა ჩატებს დაუცველი ხარვეზის გამო ასაჯაროებს

18 წყარო
  • კომპანია Adversa AI-მ xAI-ის Grok ჩატბოტში აღმოაჩინა "კრიპტოგრაფიული კონტექსტის ინექციის" ხარვეზი, რომელიც მომხმარებლის პერსონალურ მონაცემებს იპარავს, როდესაც ისინი დაინფიცირებულ ვებგვერდებს აჯამებენ.
  • შეტევა შიფრავს მავნე ინსტრუქციებს Grok-ის უსაფრთხოების ფილტრების გვერდის ავლით; ჩატბოტი მათ შიდა სისტემაში შიფრს ხსნის და გამომავალ ინფორმაციას სანდო ბრძანებებად აღიქვამს.
  • Adversa-მ შეცდომის შესახებ xAI-ს 3 ივნისს აცნობა, თუმცა The Register-ის ცნობით, 19 აგვისტოს მდგომარეობით, ექსპლოიტი Grok.com-ზე კვლავ მოქმედი იყო.
წყაროები (18)
  1. 1 Grok exfiltrates user data when malicious instructions are encrypted arstechnica.com
  2. 2 New Cryptographic Context Injection Attack Could Let Web Pages ... thehackernews.com
  3. 3 Encrypted web page payload turns Grok into a chat history leak www.cryptopolitan.com
  4. 4 Grok chat duped into swallowing injected instructions - The Register www.theregister.com
  5. 5 Grok leaks user chats when prompt injections arrive encrypted www.aichatdaily.com
  6. 6 The approval prompt is lying: a critical coding agent security flaw adversa.ai
  7. 7 Grok leaks user chats via encrypted webpage trick, 11 ... cryptorank.io
  8. 8 Grok exfiltrates user data when malicious instructions are encrypted ground.news
  9. 9 Sensitive Data Leaks From ChatGPT & Grok www.cybersecurityintelligence.com
  10. 10 Security ProbLLMs in xAI's Grok: A Deep Dive - Embrace The Red embracethered.com
  11. 11 Grok Chats Leaked: When Private AI Chats Go Public www.bladetechinc.com
  12. 12 Grok chat history leak: Cryptographic Context Injection - Adversa AI adversa.ai
  13. 13 Grok Build Repository Upload Allegations Explained | explainx.ai Blog explainx.ai
  14. 14 Adversa AI - Coding Agent Security Platform, patented AI protection adversa.ai
  15. 15 Elon Musk's xAI Published Hundreds Of Thousands Of Grok Chatbot ... www.forbes.com
  16. 16 New Cryptographic Context Injection Attack Could Let Web Pages ... community.opentextcybersecurity.com
  17. 17 Security Researchers Tricked Grok Into Leaking Users' Private Chat ... startupfortune.com
  18. 18 Encrypted Prompt Injection Attack Extracts Grok Chat Data, Researchers Say finance.biggo.com