So, I mentioned sleeper agents in a previous #infosec story, and here it is in the wild. (In a very limited, and simple trigger kinda way)
A security researcher has demonstrated how a malicious #Google #Calendar invite can prompt-inject #ChatGPT and coax it into leaking private emails once Google connectors are enabled.
Which, I mean...are there no old hackers on any of these “ai” teams? No ethicists who might point out obvious problems? Ok, we know there’s no ethicists, but come on man, a prompt injection that obvious suggests a generation of people too young to remember the early internet.
Don’t get me wrong, I blame both #OpenAI and Google. It’s just so stupid, I’m not angry...I’m just disappointed.
https://www.tomshardware.com/tech-industry/cyber-security/researcher-shows-how-comprimised-calendar-invite-can-hijack-chatgpt