if you’ve been on either side of a bug bounty you know the joy in it is gone now. it’s just AI reports coming in, AI patches going out, and decreasing human understanding of either. i wonder what is left of the security industry once the fun clever hacking parts are all
haha this reminds me that at one point during internal testing of Brave's AI agent (Leo), it refused to execute Step 3 on a todo list when Steps 1 and 2 were black text and Step 3 was white text (therefore invisible). but it got tricked into executing it when Steps 1 and 2 were
Indirect prompt injection is a fundamental security challenge for AI. It's an issue for both local and cloud-based LLMs.
After disclosing our findings to both companies, we're now sharing our analysis of Mozilla Tabstack and Cotypist today.