Live data from Hacker News

How we hacked McKinsey's AI platform

codewall.ai

51–60 of 213 posts

Re: How we hacked McKinsey's AI platform

#52

Some insider knowledge: Lilli was, at least a year ago, internal only. VPN access, SSO, all the bells and whistles, required. Not sure when that changed. McKinsey requires hiring an external pen-testing company to launch even to a small group of coworkers. I can forgive this kind of mistake on the part of the Lilli devs. A lot of things have to fail for an "agentic" security company to even find a public endpoint, mu…

Net conclusion: Don’t hire McKinsey to advise on AI implementation or tech org design and practices if they can’t get it right themselves.

Re: How we hacked McKinsey's AI platform

#55
post #21

I've got no idea who codewall is. Is there acknowledgment from McKinsey that they actually patched the issue referenced? I don't see any reference to "codewall ai" in any news article before yesterday and there's no names on the site. https://www.google.com/search?q=codewall+ai

If it's true that there's 58k users in the dump, that would mean former employees are in the dump

I assume that means McKinsey would need to disclose it, or at least alert the former employees of the breach?

Re: How we hacked McKinsey's AI platform

#56
post #34
post #16

Earlier quoted context omitted.

Yeah, gotta admit I'm a bit disappointed here. This was a run-of-the-mill SQL injection, albeit one discovered by a vulnerability scanning LLM agent. I thought we might finally have a high profile prompt injection attack against a name-brand company we could point people to.

Github actions has had a bunch of high-profile prompt injection attacks at this point, most recently the cline one: https://adnanthekhan.com/posts/clinejection/ I guess you could argue that github wasn't vulnerable in this case, but rather the author of the action, but it seems like it at least rhymes with what you're looking for.

Yeah that was a good one. The exploit was still a proof of concept though, albeit one that made it into the wild.
Post reply on HN