Загрузка...

Every AI Assistant Has the Same Flaw, and It Can't Be Fixed

Prompt injection is the AI assistant security flaw that OpenAI, Anthropic, Google, and Microsoft have all admitted, on the record, that they probably can't fully fix. It's the LLM security story the marketing pages skip: every AI assistant and AI agent that can read your email, calendar, documents, or browser shares the same unfixable flaw, because the lethal trifecta of private data, untrusted content, and outward communication means the architecture itself was built for compromise.

This video walks you through all three layers of how AI assistants actually get hacked: the direct prompt injection that broke GPT-3 in 2022 (the Riley Goodside "Haha pwned" demo + the Bing Sydney leak), the indirect prompt injection that earned EchoLeak (CVE-2025-32711) a CVSS 9.3 against Microsoft 365 Copilot, and the AI agent attack class where the agent itself becomes the attacker (the SafeBreach "Invitation Is All You Need" Gemini smart-home demo + MCP CVEs against Anthropic's mcp-remote and mcp-server-git + Brave's Perplexity Comet disclosure).

In this video you'll see:

- The sentence that jailbroke GPT-3 with one line of text
- Why every major AI lab (OpenAI, Anthropic, Google, Microsoft) has shipped layered defenses and still publishes attack-success metrics in the single-digit percentage range
- The zero-click AI vulnerability rated CVSS 9.3 that exfiltrated data from a victim who never opened the attacker's email
- Why Andrej Karpathy calls this "the wild west of early computing" and Simon Willison named the structural defense "the lethal trifecta"
- What OpenAI literally wrote about their own agent browser product: prompt injection is "unlikely to ever be fully solved"
- The structural defense: compartmentalize the lethal trifecta, treat any AI assistant with tool access like a contractor with the keys to your house, pin and review every plugin, extension, and MCP server you connect

If you use ChatGPT, Claude, Gemini, Copilot, Perplexity Comet, or any AI agent that touches your email, calendar, or browser, this is the architecture problem you need to understand before your next prompt.

🔮 My Consulting:
Post-quantum security & cryptography advisory
→ Learn more https://www.lamarrlabs.com/

🧠 My Newsletter:
→ LaMarr Labs: Biweekly notes on the post-quantum transition (PQC, timelines, what to do next). https://lamarrlabs.substack.com/
→ Addie LaMarr: Cybersecurity + tech writing (threats, tools, and the future of the internet). https://addielamarr.substack.com/

📘 My Course:
Zero to Cyber Hero: a step-by-step roadmap into cybersecurity
→ Start here https://addie-clark.mykajabi.com/zero-to-cyber-hero-waitlist-discount

🖇️ Let's Connect:
https://www.linkedin.com/in/addie-clark/

📚 Sources:
→ Simon Willison — Prompt injection (Sept 12, 2022 coining): https://simonwillison.net/2022/Sep/12/prompt-injection/
→ Simon Willison — The lethal trifecta (June 16, 2025): https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
→ Greshake et al. — Not What You've Signed Up For (foundational indirect prompt injection, arXiv): https://arxiv.org/abs/2302.12173
→ OpenAI — Hardening Atlas against prompt injection ("unlikely to ever be fully solved"): https://openai.com/index/hardening-atlas-against-prompt-injection/
→ Anthropic — Computer Use launch + day-one Caution box on prompt injection: https://www.anthropic.com/news/prompt-injection-defenses
→ Microsoft 365 Copilot EchoLeak (CVE-2025-32711, Aim Labs disclosure): https://thehackernews.com/2025/06/zero-click-ai-vulnerability-exposes.html
→ EchoLeak technical paper (Aim Labs, arXiv): https://arxiv.org/abs/2509.10540
→ SafeBreach — Invitation Is All You Need (Gemini Workspace + smart-home attack): https://www.safebreach.com/blog/invitation-is-all-you-need-hacking-gemini/
→ JFrog — mcp-remote RCE (CVE-2025-6514, CVSS 9.6): https://jfrog.com/blog/mcp-prompt-hijacking-vulnerability/
→ The Register — Three flaws in Anthropic's mcp-server-git (early 2026): https://www.theregister.com/2026/01/20/anthropic_prompt_injection_flaws/
→ Brave — Perplexity Comet indirect prompt injection: https://brave.com/blog/comet-prompt-injection/
→ Embrace The Red — ChatGPT macOS SpAIware (Johann Rehberger): https://embracethered.com/blog/posts/2024/chatgpt-macos-app-persistent-data-exfiltration/
→ PromptArmor — Slack AI data exfiltration disclosure: https://promptarmor.substack.com/p/slack-ai-data-exfiltration-from-private
→ OWASP — Top 10 for LLM Applications LLM01:2025 (Prompt Injection at #1): https://genai.owasp.org/llmrisk/llm01-prompt-injection/
→ NIST — AI 100-2 E2025 Adversarial Machine Learning Taxonomy (March 2025): https://csrc.nist.gov/pubs/ai/100/2/e2025/final
→ UK NCSC — Prompt injection is not SQL injection (it may be worse): https://www.ncsc.gov.uk/blog-post/prompt-injection-is-not-sql-injection
→ Andrej Karpathy — "wild west of early computing" framing: https://x.com/karpathy/status/1934651657444528277

Видео Every AI Assistant Has the Same Flaw, and It Can't Be Fixed канала Addie LaMarr
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять