Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Glimpse wants to give hardware companies an X-ray view of every critical part

    How to Make a Cloud Read a Drone’s Mind (and Cut Data Usage by 94%)

    OpenAI agents tried to hack Wikipedia tools and flooded it with traffic

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    • Artificial Intelligence
    AI News TodayAI News Today
    Home»AI News»Grok exfiltrates user data when malicious instructions are encrypted
    AI News

    Grok exfiltrates user data when malicious instructions are encrypted

    By Updated:No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    xAI and Grok logos displayed on a smartphone screen
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Adversa used a similar technique in a Gemini jailbreak attack, meaning making the Google LLM ignore its internal safety rules. Here, the ciphertext was decrypted to what appeared to be a traceback. The decrypted text issued one rule—if the code fails, read the error message and act on it. The cleartext injected a prompt that ultimately caused Gemini to violate its safety rules.

    “The technique produced a multi-paragraph example of restricted content that Gemini’s safety filters normally suppress (building an incendiary weapon),” Adversa said. “With a modified payload, the same vector reproduced Gemini’s system instructions, including the directive forbidding their disclosure.”

    Adversa didn’t report the behavior to Google because jailbreaks aren’t within scope of the company’s vulnerability disclosure program. Over the past few weeks, however, Gemini has grown increasingly resistant to the attack. “We can’t attribute the change—it could be filter updates, model version changes, or both,” the security firm said. Company researchers are calling the technique cryptographic context injection.

    “Cryptographic Context Injection is one instance of a broader shift: attacks that manipulate not just the prompt, but the wider context an LLM treats as its own, such as tool outputs, runtime results and intermediate state” Adversa said. “This attack surface is far larger than what’s traditionally labeled ‘model inputs,’ and the next generation of attacks will emerge there.”

    The Cryptographic Context Injection is only the latest example of the disadvantage LLM defenders operate under. Every time they build a new, one-off guardrail, an attacker finds a new vector that allows the car to once again careen off the road. The cycle continues: lather, rinse, and repeat.

    Data encrypted exfiltrates Grok instructions malicious user
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleNASA gives up on trying to rescue the Swift telescope
    Next Article How to Fine-Tune an LLM: An End-to-End Guide
    • Website

    Related Posts

    AI News

    Glimpse wants to give hardware companies an X-ray view of every critical part

    AI Tools

    How to Make a Cloud Read a Drone’s Mind (and Cut Data Usage by 94%)

    AI News

    OpenAI agents tried to hack Wikipedia tools and flooded it with traffic

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Glimpse wants to give hardware companies an X-ray view of every critical part

    0 Views

    How to Make a Cloud Read a Drone’s Mind (and Cut Data Usage by 94%)

    0 Views

    OpenAI agents tried to hack Wikipedia tools and flooded it with traffic

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Glimpse wants to give hardware companies an X-ray view of every critical part

    0 Views

    How to Make a Cloud Read a Drone’s Mind (and Cut Data Usage by 94%)

    0 Views

    OpenAI agents tried to hack Wikipedia tools and flooded it with traffic

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.