Cybersecurity researchers have identified a high-severity security flaw in the Vanna.AI library, tracked as CVE-2024-5565 with a CVSS score of 8.1, that can be exploited for remote code execution via prompt injection techniques. JFrog, a supply chain security firm, disclosed that the vulnerability lies in the "ask" function of Vanna, a Python-based machine learning library used to query SQL databases using natural language prompts. This flaw allows attackers to execute arbitrary commands by manipulating the prompt inputs. Prompt injection, a type of AI jailbreak, poses significant risks as malicious actors can bypass safety mechanisms built into AI models by providing adversarial inputs. These attacks can occur indirectly, such as through data controlled by third parties, or through multi-turn strategies like Crescendo and Skeleton Key, where the attacker gradually manipulates the AI model to disregard its guardrails and execute prohibited commands. The Skeleton Key technique is particularly dangerous as it puts the model in a mode where it complies with any instructions, regardless of the ethical and safety guidelines. Following responsible disclosure, Vanna has issued a hardening guide advising users to run the Plotly integration in a sandboxed environment to mitigate the risk. Shachar Menashe, senior director of security research at JFrog, emphasized the need for robust security mechanisms when interfacing large language models (LLMs) with critical resources, warning that the dangers of prompt injection are not yet widely recognized but are easy to exploit.
Security researchers have identified a new variant of the SparkCat malware circulating on both the Apple App Store and Google Play Store, more than a year after its initial discove...
The European Union’s cybersecurity agency, CERT-EU, has attributed a significant cloud breach involving the European Commission to the TeamPCP threat group. The attack targeted t...
Microsoft has rolled out automatic updates for unmanaged Windows 11 24H2 Home and Pro edition devices to Windows 11 25H2, also known as the Windows 11 2025 Update. This transition ...