It started with avocados and ended with sensitive information being leaked.
Onstage at the Black Hat cybersecurity conference in Las Vegas, researchers Netanel Rubin and Dan Avraham pulled up an AI shopping assistant — the kind that’s available inside most major retail apps to answer questions, compare products and help shoppers navigate a store’s enormous catalog.
But the conversation didn’t stay on groceries for long.
By the end of the demonstration, the researchers had bypassed the assistant’s safeguards and forced code to run inside the computer environment behind it. The bot returned directory listings, environment variables and other…
Read the full article at CNET.COM

