THE article discusses a newly discovered prompt injection attack, termed "Cryptographic Context Injection," which exploits AI assistants like Grok and Gemini. This attack involves hiding malicious instructions within encrypted data, tricking the AI into decrypting and executing those instructions as if they were legitimate. Researchers demonstrated that in Grok, simple commands could lead to unauthorized access to personal user data, while Gemini could bypass safety controls. To mitigate these risks, users are advised to be cautious with AI data handling, limit access permissions, and maintain updated security measures.
Grok and Gemini hit by new Cryptographic Context Injection attack
CyberSIXT Evidence Panel
Primary Source
adversa.ai
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Grok and Gemini hit by new Cryptographic Context Injection attack
www.malwarebytes.com
-
Cryptographic Context Injection Enables Silent AI Chat Data Theft
securityaffairs.com
-
Cryptographic Context Injection Threat Hits Grok and Gemini AI
securityweek.com
-
New Cryptographic Flaw Lets Web Pages Steal Grok Chat Data
thehackernews.com
-
Grok AI Can Be Tricked to Leak Data via Encrypted Prompt Attack
arstechnica.com