logo

Slack Patches AI Bug That Let Attackers Steal Data From Private Channels

ID: f053f290-007f-59e6-9705-d807284838a0

STIX ID: report--f053f290-007f-59e6-9705-d807284838a0

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-08-22

Date Updated: 2026-05-05

Author: Elizabeth Montalbano, Contributing Writer

...
...

PromptArmor reported a prompt-injection flaw in Slack AI that could let an attacker with a workspace account trick the LLM into revealing data from private channels or rendering phishing content; Slack deployed a patch after disclosure and says the issue applied in limited circumstances with no evidence of customer data access. Researchers warned the risk increased when Slack AI began ingesting uploaded documents and external files, which could be used to deliver malicious instructions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.