• Researchers found a way to trick Lenovo’s AI chatbot Lena
  • Lena shared active session cookies with the researchers
  • Malicious prompts could be used for a wide variety of attacks

Lena, the ChatGPT-powered chatbot featured on Lenovo’s website, could be turned into a malicious insider, spilling company secrets, or running malware, by using nothing more than a compelling prompt, experts have warned.

Security researchers at Cybernews managed to obtain active session cookies from human customer support agents, essentially taking over their accounts, accessing sensitive data, and potentially pivoting elsewhere in the corporate network.



Source link

Podcast also available on PocketCasts, SoundCloud, Spotify, Google Podcasts, Apple Podcasts, and RSS.