Ramp's Sheets AI Exfiltrates Financials
11–20 of 59 posts
Re: Ramp's Sheets AI Exfiltrates Financials
#12"The PromptArmor Threat Intel Team responsibly disclosed this vulnerability to Ramp. Ramp's security team indicated that the issue was resolved on May 16, 2026." I think they mean March here
Re: Ramp's Sheets AI Exfiltrates Financials
#13It's kinda awesome that after decades of software and hardware advancements to prevent computers from arbitrarily executing data as instructions, we've decided to let agents arbitrarily execute data as instructions.
Well, yeah. It's that or pay a person to do it. When a person screws up, it's because they're stupid and lazy. When an AI agent does it, it's because, hey, technological frontier at work here, have you thought about refining your prompt? We need you to refine the prompt. Otherwise it's bad for our IPO.
Re: Ramp's Sheets AI Exfiltrates Financials
#14It's kinda awesome that after decades of software and hardware advancements to prevent computers from arbitrarily executing data as instructions, we've decided to let agents arbitrarily execute data as instructions.
We're in the same era where lots of peoples' installation guides for the software they want people to use is essentially boiled down to "sudo curl | bash" and/or just "blindly install this thing with 37 npm dependencies", so I'm not surprised in the slightest. But wait, hold my beer, now we've got people turning openclaw type tools loose in their systems to do things as sudo or install software packages from supply-c…
Re: Ramp's Sheets AI Exfiltrates Financials
#15Earlier quoted context omitted.
Well, yeah. It's that or pay a person to do it. When a person screws up, it's because they're stupid and lazy. When an AI agent does it, it's because, hey, technological frontier at work here, have you thought about refining your prompt? We need you to refine the prompt. Otherwise it's bad for our IPO.
To what degree am I required to participate in mass delusions?
Re: Ramp's Sheets AI Exfiltrates Financials
#16What about this is a vulnerability, let alone one that requires responsible disclosure? Untrusted data sources can provide data that causes bad things to occur. If that's a vulnerability, then any application that ingests data is riddled with vulnerabilities. I agree that the behavior should change from a default of allowing external network requests to denying them, but this "report" reads like overly dramatic marke…
For example https://en.wikipedia.org/wiki/Melissa_(computer_virus)
Re: Ramp's Sheets AI Exfiltrates Financials
#17What about this is a vulnerability, let alone one that requires responsible disclosure? Untrusted data sources can provide data that causes bad things to occur. If that's a vulnerability, then any application that ingests data is riddled with vulnerabilities. I agree that the behavior should change from a default of allowing external network requests to denying them, but this "report" reads like overly dramatic marke…
Re: Ramp's Sheets AI Exfiltrates Financials
#18It's kinda awesome that after decades of software and hardware advancements to prevent computers from arbitrarily executing data as instructions, we've decided to let agents arbitrarily execute data as instructions.
You gave it capability to delete emails. Why did you expect it not to do that at least some of the time? And with enough user some of the time will most likely happen...
Re: Ramp's Sheets AI Exfiltrates Financials
#19"The PromptArmor Threat Intel Team responsibly disclosed this vulnerability to Ramp. Ramp's security team indicated that the issue was resolved on May 16, 2026." I think they mean March here
Maybe AGI figured out time travel?
Re: Ramp's Sheets AI Exfiltrates Financials
#20What about this is a vulnerability, let alone one that requires responsible disclosure? Untrusted data sources can provide data that causes bad things to occur. If that's a vulnerability, then any application that ingests data is riddled with vulnerabilities. I agree that the behavior should change from a default of allowing external network requests to denying them, but this "report" reads like overly dramatic marke…
There's an important difference between "the import had bad numbers so the report is wrong" versus "the import had a virus and now our network is compromised."
They are not the same kind of failure, they don't have the same impacts, and they don't involve the same mechanisms for prevention, detection, or remediation.