
Recent findings by cybersecurity researchers, including those at Hidden Layer Security (@hiddenlayersec) and Salt Security, have exposed significant vulnerabilities in large language models (LLMs) and their plugins, particularly those developed by Google and OpenAI. The Gemini Advanced Google Workspace plugin, associated with Google's Gemini LLM, has been found vulnerable to leaking system instructions and indirect prompt injection attacks. Similarly, critical security flaws in ChatGPT plugins, highlighted by Oracle (@OracleNYSE) and Microsoft's OpenAI ($MSFT OpenAI), have been identified, putting users at risk of data breaches, including the potential theft of login details and access to sensitive data on third-party websites. Further research has revealed vulnerabilities in closed AI models from both OpenAI and Google, highlighting the risk of attackers exploiting these flaws to install malicious plugins without user consent and hijack accounts on platforms like GitHub. Additionally, it was noted by IEthics that, with the exception of Google Gemini, all widely used chat-based LLMs transmit tokens immediately after generating them, creating a side channel vulnerability. However, Google Gemini is exempt from this issue. OpenAI and Cloudflare have implemented fixes to address these security concerns.
Researchers have uncovered new threat in third-party plugins for OpenAI's #ChatGPT that could allow attackers to install malicious plugins without users' consent and hijack accounts on third-party websites such as GitHub. Read: https://t.co/hNSaX2cndY #cybersecurity #technews
Researchers detail a side channel that can be used to read encrypted responses from AI assistants, except Google Gemini; OpenAI and Cloudflare implemented fixes (@dangoodin001 / Ars Technica) https://t.co/kT0wW47fHj 📫 Subscribe: https://t.co/OyWeKSRpIM https://t.co/ificKyWfSs
"With the exception of Google Gemini, all widely available chat-based #LLMs transmit tokens immediately after generating them... This real-time design plays a key role in creating the side channel": https://t.co/JJ1C4nBcfD #ethics #AI #privacy #cybersec #tech #research #business
