← Back to feed
Breaches & RansomwareEmerging1 sourceJan 18, 2024 · 11:00via Embrace The Red (AI agent security)

AWS Fixes Data Exfiltration Attack Angle in Amazon Q for Business

Brief

A few weeks ago Amazon released the Preview of Amazon Q for Business, and after looking at it I found a data exfiltration angle via rendering markdown/hyperlinks and reported it to Amazon.

Amazon reacted quickly and mitigated the problem. This post shares further details and how it was fixed.

The Problem

An Indirect Prompt Injection attack can cause the LLM to return markdown tags. This allows an adversary who’s data makes it into the chat context (e. g via an uploaded file) to achieve data exfiltration of the victim’s data by rendering hyperlinks.

Read more on Embrace The Red (AI agent security)