logo

Eurostar Accused Researchers of Blackmail for Reporting AI Chatbot Flaws

ID: a1a5a3f5-7459-5ad1-a76a-7640a36c2f5f

STIX ID: report--a1a5a3f5-7459-5ad1-a76a-7640a36c2f5f

Feed Name: HackRead

Threat Score
55/100

Date Published: 2025-12-24

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Researchers at Pen Test Partners disclosed multiple security flaws in Eurostar's AI chatbot — a design flaw that only checked the last message allowed guardrail bypass and prompt injection (revealing internal instructions and model details), plus HTML injection and unverified conversation IDs that could enable session replay or content injection; the issues were reported to Eurostar, eventually patched, and the case underscores that traditional web security remains crucial for AI frontends.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.