eupolicy.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
This Mastodon server is a friendly and respectful discussion space for people working in areas related to EU policy. When you request to create an account, please tell us something about you.

Server stats:

196
active users

#perplexity

10 posts10 participants0 posts today

"While looking at Comet, we discovered vulnerabilities which we reported to Perplexity, and which underline the security challenges faced by agentic AI implementations in browsers. The attack demonstrates how easy it is to manipulate AI assistants into performing actions that were prevented by long-standing Web security techniques, and how users need new security and privacy protections in agentic browsers.

The vulnerability we’re discussing in this post lies in how Comet processes webpage content: when users ask it to “Summarize this webpage,” Comet feeds a part of the webpage directly to its LLM without distinguishing between the user’s instructions and untrusted content from the webpage. This allows attackers to embed indirect prompt injection payloads that the AI will execute as commands. For instance, an attacker could gain access to a user’s emails from a prepared piece of text in a page in another tab."

brave.com/blog/comet-prompt-in

Brave · Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet | BraveThe attack we developed shows that traditional Web security assumptions don't hold for agentic AI, and that we need new security and privacy architectures for agentic browsing.

Mittwoch ist Weekly-Tag! Unsere neue Podcast-Folge ist draußen. Es geht um:

- Perplexitys Angebot, Chrome zu kaufen. Wer steckt hinter dem KI-Startup? Das erklärt mein Kollege Florian Zandt von @t3n

Außerdem berichtet @ghonsel von positiven Klima-Kipppunkte. Unser Tipp der Woche sind diesmal Tools zur Playlisten-Musik-Übertragung. Ihr wisst, warum 😉

Hört gern mal rein. 🎙️

#Podcast #Perplexity #Klima #Spotify

mittechnologyreview.podigee.io