Data Exfiltration from Slack AI via indirect prompt injection

Slack AI is vulnerable to prompt injection attacks, allowing data exfiltration from private channels and phishing attempts. Slack’s response that this is “intended behavior” is concerning and highlights the industry’s struggle to grasp prompt injection’s severity.

Posted on 28 Sep 2024