Fast injection flaw in Vanna AI exposes databases to RCE attacks

Prompt Injection Flaw

Cybersecurity researchers have discovered a high-severity vulnerability in the Vanna.AI library that could be exploited to create remote code execution vulnerabilities via prompt injection techniques. The vulnerability, tracked as CVE-2024-5565 (CVSS score: 8.1), involves a case of fast injection in the “ask” function that can be abused to trick the library into executing arbitrary commands, … Read more

Microsoft updates controversial AI-powered recall feature due to privacy concerns

AI-Powered Recall

June 8, 2024NewsroomArtificial intelligence/privacy Microsoft said Friday it will disable the much-criticized artificial intelligence (AI)-based Recall feature by default and make it opt-in. Currently in preview and available exclusively for Copilot+ PCs on June 18, 2024, Recall functions as an “explorable visual timeline” by taking screenshots of what appears on users’ screens every five seconds, … Read more