Urgent.News

What's breaking now, across thousands of outlets.

More in AI

Your LLM's Input Filter Can't Read Ciphertext. That's the Whole Exploit.

Grok walked a user's name, coarse location, subscription tier, and chat history out to an attacker's server using instructions its own guardrails had already rejected. Same words, same intent.

  • Grok AI model leaked user data via encrypted payload to attacker's server
  • Exploit bypassed filters by encrypting JSON blob with AES-256-GCM
  • Solution involves post-transformation scan on sandbox's output

More from Friday 28 August →