Slack AI Can Be Tricked Into Leaking Data From Private Channels

slack-ai-can-be-tricked-into-leaking-data-from-private-channels
Slack AI Can Be Tricked Into Leaking Data From Private Channels

Posted by msmash from the closer-look dept.

Slack AI, an add-on assistive service available to users of Salesforce’s team messaging service, is vulnerable to prompt injection, according to security firm PromptArmor. From a report: The AI service provides generative tools within Slack for tasks like summarizing long conversations, finding answers to questions, and summarizing rarely visited channels.

“Slack AI uses the conversation data already in Slack to create an intuitive and secure AI experience tailored to you and your organization,” the messaging app provider explains in its documentation. Except it’s not that secure, as PromptArmor tells it. A prompt injection vulnerability in Slack AI makes it possible to fetch data from private Slack channels.

Top Ten Things Overheard At The ANSI C Draft Committee Meetings: (4) How many times do we have to tell you, “No prior art!”

Working…