Eurostar Accused Researchers of Blackmail for Reporting AI Chatbot Flaws
ID: a1a5a3f5-7459-5ad1-a76a-7640a36c2f5f
STIX ID: report--a1a5a3f5-7459-5ad1-a76a-7640a36c2f5f
Feed Name: HackRead
**Researchers at Pen Test Partners disclosed multiple security flaws in Eurostar's AI chatbot — a design flaw that only checked the last message allowed guardrail bypass and prompt injection (revealing internal instructions and model details), plus HTML injection and unverified conversation IDs that could enable session replay or content injection; the issues were reported to Eurostar, eventually patched, and the case underscores that traditional web security remains crucial for AI frontends.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
