Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations

Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations

submitted by /u/HyprWave [link] [comments]
Ran a structured adversarial test against a live chatbot endpoint - 130 prompts across four categories: prompt injection, jailbreak resistance, system prompt extraction, and PII leakage (mapped to the OWASP LLM Top 10 categories). Results: Prompt injection: 29/50 succeeded (58%) - direct overrides, fake system tags, role overrides, delimiter injection, and a translation-based smuggling trick all worked Jailbreak non-refusal: 3/25 (12%) - mostly held its guardrails System prompt extraction: 0/25 (0%) - clean PII leakage (confirmed against planted canary values): 1/30 (3.33%) - one confirmed leβ¦
At Bug Bounty Village during DEF CON 34, Inti De Ceukelaire delivered a talk on how attackers can abuse today's AI agents in ways most defenders haven't thought about yet, from tricking agents into spilling secrets to forcing them to carry out unauthorized actions on behalf of the victim. This resulted in over $50,000+ in bounties in just a few weekends, without actually poking the target with Burp Suite or any automated scanners. submitted by /u/qwerty0x41 [link] [comments]