PulseAugur
中
实时 11:12:35
English(EN) Zero-Click # Grok Chat History Theft: Adversa AI Demonstrates # Cryptographic # Context # Injection https:// securityaffairs.com/197717/hac king/zero-click-grok

Grok AI 聊天机器人易受通过加密提示注入的零点击数据盗窃攻击

Adversa AI 的研究人员在 xAI 的 Grok 聊天机器人中发现了一个零点击漏洞,该漏洞允许攻击者窃取用户聊天记录和其他敏感数据。该漏洞利用在 AES-256-GCM 加密文本中嵌入恶意命令,Grok 会解密并使用其 Python 代码执行环境执行这些命令。这使得聊天机器人在没有任何用户交互的情况下,将用户名、位置和订阅级别等数据泄露到攻击者控制的目的地。 AI

影响 此漏洞凸显了具有代码执行和数据访问能力的 AI 代理所带来的风险,可能加速了对 AI 开发中更严格安全协议的需求。

排序理由 安全研究人员披露了现有 AI 产品中的一个漏洞。

在 Mastodon — fosstodon.org 阅读 →

AI 生成摘要 · Google Gemini · 来自 2 个来源。 我们如何撰写摘要 →

Grok AI 聊天机器人易受通过加密提示注入的零点击数据盗窃攻击

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
安全研究人员披露了现有 AI 产品中的一个漏洞。
Source corroboration
2 independent sources
Multiple independent publishers reporting the same story raises confidence that it's real and newsworthy.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
46 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

完整方法见我们的编辑标准。

报道来源 [2]

  1. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    零点击 # Grok 聊天记录盗窃:Adversa AI 演示 # 加密 # 上下文 # 注入 https:// securityaffairs.com/197717/hacking/zero-click-grok

    Zero-Click # Grok Chat History Theft: Adversa AI Demonstrates # Cryptographic # Context # Injection https:// securityaffairs.com/197717/hac king/zero-click-grok-chat-history-theft-adversa-ai-demonstrates-cryptographic-context-injection.html # securityaffairs # hacking # AI # Gemi…

  2. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    Grok AI聊天机器人通过加密提示注入被诱骗泄露私人聊天内容 Adversa AI的研究人员在xAI的Grok中发现了一个零点击漏洞

    Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack needs no …