Grok Zero-Click Attack: Critical Data Theft Risk
ID: cda94607-1de9-5a78-9f16-4c72fc6cc825
STIX ID: report--cda94607-1de9-5a78-9f16-4c72fc6cc825
Feed Name: CyberNexora News
**Grok Zero-Click Attack:** Researchers disclosed a cryptographic prompt injection technique where encrypted instructions embedded in webpages are decrypted by an AI agent (Grok), potentially causing the agent to treat the decrypted content as trusted tool output and exfiltrate session data (user name, coarse location, subscription tier, conversation content) via browsing capabilities; the technique was reproducible in tests (~40% success) but had no reported CVE or confirmed real-world exploitation at disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
