Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft
ID: f6e13b9a-c3e6-573b-82d3-cd586116a67c
STIX ID: report--f6e13b9a-c3e6-573b-82d3-cd586116a67c
Feed Name: Dark Reading
Threat Score
Google patched a critical Dialogflow CX vulnerability called "Rogue Agent" disclosed by Varonis, where abuse of the Code Blocks feature and the dialogflow.playbooks.update permission could let an attacker inject persistent malicious code to exfiltrate conversations and facilitate large-scale phishing; the issue has been fixed and there are no known compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
