Slack Patches AI Bug That Let Attackers Steal Data From Private Channels
ID: f053f290-007f-59e6-9705-d807284838a0
STIX ID: report--f053f290-007f-59e6-9705-d807284838a0
Feed Name: Dark Reading
Date Published: 2024-08-22
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
PromptArmor reported a prompt-injection flaw in Slack AI that could let an attacker with a workspace account trick the LLM into revealing data from private channels or rendering phishing content; Slack deployed a patch after disclosure and says the issue applied in limited circumstances with no evidence of customer data access. Researchers warned the risk increased when Slack AI began ingesting uploaded documents and external files, which could be used to deliver malicious instructions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
