Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    5 startups that caught VCs’ attention at the latest PearX demo day

    I Hid Four Traps in a Forecasting Task. Here Is What Four AI Assistants Did.

    Kevin Roose Didn’t Use AI to Write His Book About AI

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    • Artificial Intelligence
    AI News TodayAI News Today
    Home»AI News»Grok exfiltrates user data when malicious instructions are encrypted
    AI News

    Grok exfiltrates user data when malicious instructions are encrypted

    By Updated:No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    xAI and Grok logos displayed on a smartphone screen
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Adversa used a similar technique in a Gemini jailbreak attack, meaning making the Google LLM ignore its internal safety rules. Here, the ciphertext was decrypted to what appeared to be a traceback. The decrypted text issued one rule—if the code fails, read the error message and act on it. The cleartext injected a prompt that ultimately caused Gemini to violate its safety rules.

    “The technique produced a multi-paragraph example of restricted content that Gemini’s safety filters normally suppress (building an incendiary weapon),” Adversa said. “With a modified payload, the same vector reproduced Gemini’s system instructions, including the directive forbidding their disclosure.”

    Adversa didn’t report the behavior to Google because jailbreaks aren’t within scope of the company’s vulnerability disclosure program. Over the past few weeks, however, Gemini has grown increasingly resistant to the attack. “We can’t attribute the change—it could be filter updates, model version changes, or both,” the security firm said. Company researchers are calling the technique cryptographic context injection.

    “Cryptographic Context Injection is one instance of a broader shift: attacks that manipulate not just the prompt, but the wider context an LLM treats as its own, such as tool outputs, runtime results and intermediate state” Adversa said. “This attack surface is far larger than what’s traditionally labeled ‘model inputs,’ and the next generation of attacks will emerge there.”

    The Cryptographic Context Injection is only the latest example of the disadvantage LLM defenders operate under. Every time they build a new, one-off guardrail, an attacker finds a new vector that allows the car to once again careen off the road. The cycle continues: lather, rinse, and repeat.

    Data encrypted exfiltrates Grok instructions malicious user
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleNASA gives up on trying to rescue the Swift telescope
    Next Article How to Fine-Tune an LLM: An End-to-End Guide
    • Website

    Related Posts

    AI News

    5 startups that caught VCs’ attention at the latest PearX demo day

    AI News

    Hot Girl Hotline is like ‘Dear Abby’ for the AI era

    AI News

    At 19, founder raises $11M for Ghost, maker of a $3,499 computer for personal AI

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    5 startups that caught VCs’ attention at the latest PearX demo day

    0 Views

    I Hid Four Traps in a Forecasting Task. Here Is What Four AI Assistants Did.

    0 Views

    Kevin Roose Didn’t Use AI to Write His Book About AI

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    5 startups that caught VCs’ attention at the latest PearX demo day

    0 Views

    I Hid Four Traps in a Forecasting Task. Here Is What Four AI Assistants Did.

    0 Views

    Kevin Roose Didn’t Use AI to Write His Book About AI

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.