To Know
-
Features and Updates
Keep an eye out
CALL to Community
Oct 2024
To Know
-
Features and Updates
Keep an eye out
CALL to Community
Oct 2024
EDITION EDITORIAL & OVERVIEW
Features and Updates
#
58
CALL to Community
-
Oct 2024

Hacker plants false memories in ChatGPT to steal user data in perpetuity?

Recently, a vulnerability was discovered in OpenAI's ChatGPT that exploited its long-term conversation memory feature. This feature, which stores information from previous conversations to provide context in future interactions, was found to be susceptible to indirect prompt injection. Researcher Rehberger demonstrated that malicious actors could manipulate ChatGPT into storing false information, such as a user’s age or beliefs, by embedding instructions in untrusted content like emails or documents. This could lead to the AI incorporating these false details into all future conversations.

This vulnerability was reported to OpenAI in May, with a proof of concept showing how the ChatGPT macOS app could be exploited to send user data to an attacker’s server. Source here.

Here at Celfocus, we require users to follow the best practices whenever using Artificial Intelligence software such as ChatGPT and Microsoft Copilot, by not sharing any confidential information into prompts.

Word of the Edition – Update

Update refers to making something more modern or suitable for use at the present, by adding new information or changing its design.

Just as you need to eventually change (or update) your car’s tires to ensure your safety on the road, so too must you update your devices to prevent any vulnerabilities to be exploited by malicious actors. These updates are usually automatically done, however there are some that most likely aren’t and still need to be done.

Consider the following checklist of common updates that you can figure out if can be done on your device:

  1. Install the latest Security updates by Checking for updates on your Settings page;
  2. Search for new updates on Office 365 by going to your Account tab on any Office app and selecting the Update Options;
  3. Also, don’t forget to frequently update your browser and apps to prevent vulnerabilities.

Join the challenges

  • Can you spot a Smish?

With this challenge, you will test your knowledge and try to figure out if a text message you receive is a scam attempt or legitimate.

  • Can you spot the danger signs?

With this challenge, you have to identify what makes an email suspicious and decide whether to report it or trust it.

Information Security Contacts

We have a dedicated Security team that works diligently to ensure the protection of our systems, data, and the overall cybersecurity posture of the organization.

Should you have any questions, concerns, or need assistance regarding security matters, our team is here to help. Please find below the contact information for our Information Security team:

Email: information.security@celfocus.com

No items found.
No items found.

Hacker plants false memories in ChatGPT to steal user data in perpetuity?

Recently, a vulnerability was discovered in OpenAI's ChatGPT that exploited its long-term conversation memory feature. This feature, which stores information from previous conversations to provide context in future interactions, was found to be susceptible to indirect prompt injection. Researcher Rehberger demonstrated that malicious actors could manipulate ChatGPT into storing false information, such as a user’s age or beliefs, by embedding instructions in untrusted content like emails or documents. This could lead to the AI incorporating these false details into all future conversations.

This vulnerability was reported to OpenAI in May, with a proof of concept showing how the ChatGPT macOS app could be exploited to send user data to an attacker’s server. Source here.

Here at Celfocus, we require users to follow the best practices whenever using Artificial Intelligence software such as ChatGPT and Microsoft Copilot, by not sharing any confidential information into prompts.

Word of the Edition – Update

Update refers to making something more modern or suitable for use at the present, by adding new information or changing its design.

Just as you need to eventually change (or update) your car’s tires to ensure your safety on the road, so too must you update your devices to prevent any vulnerabilities to be exploited by malicious actors. These updates are usually automatically done, however there are some that most likely aren’t and still need to be done.

Consider the following checklist of common updates that you can figure out if can be done on your device:

  1. Install the latest Security updates by Checking for updates on your Settings page;
  2. Search for new updates on Office 365 by going to your Account tab on any Office app and selecting the Update Options;
  3. Also, don’t forget to frequently update your browser and apps to prevent vulnerabilities.

Join the challenges

  • Can you spot a Smish?

With this challenge, you will test your knowledge and try to figure out if a text message you receive is a scam attempt or legitimate.

  • Can you spot the danger signs?

With this challenge, you have to identify what makes an email suspicious and decide whether to report it or trust it.

Information Security Contacts

We have a dedicated Security team that works diligently to ensure the protection of our systems, data, and the overall cybersecurity posture of the organization.

Should you have any questions, concerns, or need assistance regarding security matters, our team is here to help. Please find below the contact information for our Information Security team:

Email: information.security@celfocus.com

No items found.
No items found.

Hacker plants false memories in ChatGPT to steal user data in perpetuity?

Recently, a vulnerability was discovered in OpenAI's ChatGPT that exploited its long-term conversation memory feature. This feature, which stores information from previous conversations to provide context in future interactions, was found to be susceptible to indirect prompt injection. Researcher Rehberger demonstrated that malicious actors could manipulate ChatGPT into storing false information, such as a user’s age or beliefs, by embedding instructions in untrusted content like emails or documents. This could lead to the AI incorporating these false details into all future conversations.

This vulnerability was reported to OpenAI in May, with a proof of concept showing how the ChatGPT macOS app could be exploited to send user data to an attacker’s server. Source here.

Here at Celfocus, we require users to follow the best practices whenever using Artificial Intelligence software such as ChatGPT and Microsoft Copilot, by not sharing any confidential information into prompts.

Word of the Edition – Update

Update refers to making something more modern or suitable for use at the present, by adding new information or changing its design.

Just as you need to eventually change (or update) your car’s tires to ensure your safety on the road, so too must you update your devices to prevent any vulnerabilities to be exploited by malicious actors. These updates are usually automatically done, however there are some that most likely aren’t and still need to be done.

Consider the following checklist of common updates that you can figure out if can be done on your device:

  1. Install the latest Security updates by Checking for updates on your Settings page;
  2. Search for new updates on Office 365 by going to your Account tab on any Office app and selecting the Update Options;
  3. Also, don’t forget to frequently update your browser and apps to prevent vulnerabilities.

Join the challenges

  • Can you spot a Smish?

With this challenge, you will test your knowledge and try to figure out if a text message you receive is a scam attempt or legitimate.

  • Can you spot the danger signs?

With this challenge, you have to identify what makes an email suspicious and decide whether to report it or trust it.

Information Security Contacts

We have a dedicated Security team that works diligently to ensure the protection of our systems, data, and the overall cybersecurity posture of the organization.

Should you have any questions, concerns, or need assistance regarding security matters, our team is here to help. Please find below the contact information for our Information Security team:

Email: information.security@celfocus.com

No items found.
No items found.
Go Back
Let Us Know Your Thoughts About Our Newsletter!
Start by
Saying Hi!
© 2024 Celfocus. All rights reserved.
Let Us Know Your Thoughts About Our Newsletter!
Start by
Saying Hi!
© 2024 Celfocus. All rights reserved.
66
20
into-the-sky
25
hanging-on
30
group-dynamics
40
classic
45
day-of-rage
50
eccentric
55
customer-experience
97
open-source
85
communities-of-practice
60
changeling
100
the-cornerstone-of-engineering-advancements
75
bpi
70
nice-to-meet-you-58
80
ai-powered-excellence-project
98
pushing-boundaries
99
fostering-collaboration
66
features-and-updates
90
bridging-the-gap
64
goingon