How we hacked McKinsey's AI platform
51–60 of 213 posts
Re: How we hacked McKinsey's AI platform
#52Some insider knowledge: Lilli was, at least a year ago, internal only. VPN access, SSO, all the bells and whistles, required. Not sure when that changed. McKinsey requires hiring an external pen-testing company to launch even to a small group of coworkers. I can forgive this kind of mistake on the part of the Lilli devs. A lot of things have to fail for an "agentic" security company to even find a public endpoint, mu…
Re: How we hacked McKinsey's AI platform
#53Re: How we hacked McKinsey's AI platform
#54Re: How we hacked McKinsey's AI platform
#55I've got no idea who codewall is. Is there acknowledgment from McKinsey that they actually patched the issue referenced? I don't see any reference to "codewall ai" in any news article before yesterday and there's no names on the site. https://www.google.com/search?q=codewall+ai
I assume that means McKinsey would need to disclose it, or at least alert the former employees of the breach?
Re: How we hacked McKinsey's AI platform
#56Earlier quoted context omitted.
Yeah, gotta admit I'm a bit disappointed here. This was a run-of-the-mill SQL injection, albeit one discovered by a vulnerability scanning LLM agent. I thought we might finally have a high profile prompt injection attack against a name-brand company we could point people to.
Github actions has had a bunch of high-profile prompt injection attacks at this point, most recently the cline one: https://adnanthekhan.com/posts/clinejection/ I guess you could argue that github wasn't vulnerable in this case, but rather the author of the action, but it seems like it at least rhymes with what you're looking for.
Re: How we hacked McKinsey's AI platform
#57Re: How we hacked McKinsey's AI platform
#58[flagged]
Re: How we hacked McKinsey's AI platform
#59Re: How we hacked McKinsey's AI platform
#60[flagged]