The popularity of AI and LLM chabots are a good thing. We also cannot ignore the fact that malicious users can use them to advance their objectives. Malicious websites are still out there. In this context, these fake websites are not what they claim to be. And, just so you know, some low-cost phones can ship with malware.
I know that if you're a frequent reader of this series, this should not be news to you. Still, I think I should bring it to your attention, again.
From the article: Actual prompt injection attacks tend to target sensitive systems that handle backend data or have administrative privileges. While the target is harder to access than a standard chatbot, the nature of the attack remains the same.
Consider a backend chatbot that helps HR organize employee data. It's on a secure network and doesn't interact with customers in any capacity.
An attacker who gains access to that secure system could exploit that improperly secured chatbot by modifying its instructions.
A good tool in the hands of a malicious user is not a good thing. This is a clear example.
Here is what's going on:
The Grok connection sounds complicated, but the basic idea is pretty straightforward. Malware often tries to make sure it starts again after you reboot your computer.
Security researchers call that persistence. x47.c includes what its seller calls an "AI Stealth" feature. According to Qrator, it can use Grok to look at the state of the infected computer and select from a predefined list of ways to maintain that access.
What I will say is this: if you need the websites of these LLM chabots, go straight to their website. Don't search for them online.
Here is why:
The malicious pages target agency staff, media buyers, and administrators with accounts that extend to multiple downstream clients. These accounts also typically allow attackers to spend available balances on fraudulent ad campaigns or resell them to other cybercriminals for significant amounts.
They are: urgency, emails about your account, payment requests, and pushback.
For example: One of the most common scams are emails about your account. It's more terrifying now because they look so legit. I've caught myself second-guessing multiple times because some emails just look too realistic. It could be anything from threats about locking your account to resetting your password because there's been a data breach.
This is not a warning that low-cost phones are a bad thing that you should avoid. Rather, it shows what attackers are ready to do when they want malware installed on your phone.
Here is a bit about the malware:
The malware is embedded directly into the firmware of low-cost Android devices using MediaTek chipsets, giving it system-level privileges that allow it to install and remove applications, grant sensitive permissions, and execute remotely downloaded code without user interaction.
His concern is that AI could accelerate math discoveries that can weaken some cryptographic systems. This means that, with AI, some things that we might think will take time, could be a possibility in a fraction of that time. And I am sure that you can relate. Are you thinking of writing an article? Before that might take time. In an environment where AI is allowed, that will take seconds. I mean SECONDS.
Buterin's argument draws on the history of integer factorization. Improved algorithms made factoring substantially easier than earlier approaches suggested, changing the security calculations behind RSA and encouraging larger keys. He suggested that AI could compress decades of comparable progress into a much shorter period
Cover photo by Debby Hudson on Unsplash. That's it for this week, and I'll see you next time.