all InfoSec news
Indirect Prompt Injection via YouTube Transcripts
May 14, 2023, 7:01 a.m. |
Embrace The Red embracethered.com
They start showing up in many places.
A new unique one that I ran across is YouTube transcripts. ChatGPT (via Plugins) can access YouTube transcripts. Which is pretty neat. However, as expected (and predicted by many researches) all these quickly built tools and integrations introduce Indirect Prompt Injection vulnerabilities.
Proof of Concept Here is how it looks with ChatGPT end to end with a demo example.
access chatgpt injection places plugins problem prompt injection quickly start tools youtube
More from embracethered.com / Embrace The Red
ChatGPT: Hacking Memories with Prompt Injection
1 week, 3 days ago |
embracethered.com
Pivot to the Clouds: Cookie Theft in 2024
2 weeks, 3 days ago |
embracethered.com
Bobby Tables but with LLM Apps - Google NotebookML Data Exfiltration
1 month, 2 weeks ago |
embracethered.com
HackSpaceCon 2024: Short Trip Report, Slides and Rocket Launch
1 month, 2 weeks ago |
embracethered.com
ASCII Smuggler - Improvements
2 months, 4 weeks ago |
embracethered.com
Jobs in InfoSec / Cybersecurity
CyberSOC Technical Lead
@ Integrity360 | Sandyford, Dublin, Ireland
Cyber Security Strategy Consultant
@ Capco | New York City
Cyber Security Senior Consultant
@ Capco | Chicago, IL
Sr. Product Manager
@ MixMode | Remote, US
Corporate Intern - Information Security (Year Round)
@ Associated Bank | US WI Remote
Senior Offensive Security Engineer
@ CoStar Group | US-DC Washington, DC