How we hacked McKinsey's AI platform
21–30 of 213 posts
Re: How we hacked McKinsey's AI platform
#22I don’t love the title here. Maybe this is a “me” problem, but when I see “AI agent does X,” the idea that it might be one of those molt-y agents with obfuscated ownership pops into my head. In this case, a group of pentesters used an AI agent to select McKinsey and then used the AI agent to do the pentesting. While it is conventional to attribute actions to inanimate objects (car hits pedestrians), IMO we should be…
Re: How we hacked McKinsey's AI platform
#23> One of those unprotected endpoints wrote user search queries to the database. The values were safely parameterised, but the JSON keys — the field names — were concatenated directly into SQL. I was expecting prompt injection, but in this case it was just good ol' fashioned SQL injection, possible only due to the naivety of the LLM which wrote McKinsey's AI platform.
Re: How we hacked McKinsey's AI platform
#24Re: How we hacked McKinsey's AI platform
#25Not exactly clear from the link: were they doing red team work for McKinsey or is this just "we found a company we thought wouldn't get us arrested and ran an AI vuln detector over their stuff"? You'd think that the world's "most prestigious consulting firm" would have already had someone doing this sort of work for them.
Re: How we hacked McKinsey's AI platform
#26Cool but impossible to read with all the LLM-isms
> No credentials. No insider knowledge. And no human-in-the-loop. Just a domain name and a dream.
It just sounds so stupid.
Re: How we hacked McKinsey's AI platform
#27Re: How we hacked McKinsey's AI platform
#28Re: How we hacked McKinsey's AI platform
#29I don’t love the title here. Maybe this is a “me” problem, but when I see “AI agent does X,” the idea that it might be one of those molt-y agents with obfuscated ownership pops into my head. In this case, a group of pentesters used an AI agent to select McKinsey and then used the AI agent to do the pentesting. While it is conventional to attribute actions to inanimate objects (car hits pedestrians), IMO we should be…
Re: How we hacked McKinsey's AI platform
#30I don’t love the title here. Maybe this is a “me” problem, but when I see “AI agent does X,” the idea that it might be one of those molt-y agents with obfuscated ownership pops into my head. In this case, a group of pentesters used an AI agent to select McKinsey and then used the AI agent to do the pentesting. While it is conventional to attribute actions to inanimate objects (car hits pedestrians), IMO we should be…
You're doing that by calling them "agentic systems".