| |
A security vulnerability in banking AI assistants allows attackers to execute phishing attacks by embedding malicious instructions in transaction descriptions—requiring only a minimal bank transfer to compromise the system. When users query the AI assistant about their transactions, the injected prompts are processed by the underlying language model and can manipulate the assistant into sending credible, personalized phishing messages that appear to come from the bank itself. This indirect prompt injection vulnerability represents a broader architectural challenge for financial institutions deploying AI assistants that process untrusted external data like transaction records and customer information.
Read Full Article →
← More Tech news