Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Android 16’s stable release is right around the corner

14 May 2025

Google Announces Material 3 Expressive With Updated Dynamic Colour Themes for Android

14 May 2025

The powerful HP Omen Max 16 gaming laptop with RTX 5070 Ti is $350 off today

14 May 2025
Facebook X (Twitter) Instagram
Just In
  • Android 16’s stable release is right around the corner
  • Google Announces Material 3 Expressive With Updated Dynamic Colour Themes for Android
  • The powerful HP Omen Max 16 gaming laptop with RTX 5070 Ti is $350 off today
  • Top HP Coupon Codes for May
  • Nubia Z70S Ultra With Snapdragon 8 Elite SoC, 64-Megapixel Telephoto Camera Goes Global
  • Sandisk WD Black SN8100 NVMe SSD With Up to 14.9Gbps Read Speeds Launched in India
  • No, a lifetime VPN subscription doesn’t mean ‘your’ lifetime
  • Jessica Jones is back: Krysten Ritter to appear in Daredevil: Born Again season 2
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » Slack could be snooping in on your private conversations
News

Slack could be snooping in on your private conversations

News RoomBy News Room22 August 20242 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

When ChatGTP was added to Slack, it was meant to make users’ lives easier by summarizing conversations, drafting quick replies, and more. However, according to security firm PromptArmor, trying to complete these tasks and more could breach your private conversations using a method called “prompt injection.”

The security firm warns that by summarizing conversations, it can also access private direct messages and deceive other Slack users into phishing. Slack also lets users request grab data from private and public channels, even if the user has not joined them. What sounds even scarier is that the Slack user does not need to be in the channel for the attack to function.

In theory, the attack starts with a Slack user tricking the Slack AI into disclosing a private API key by making a public Slack channel with a malicious prompt. The newly created prompt tells the AI to swap the word “confetti” with the API key and send it to a particular URL when someone asks for it.

The situation has two parts: Slack updated the AI system to scrape data from file uploads and direct messages. Second is a method named “prompt injection,” which PromptArmor proved can make malicious links that may phish users.

The technique can trick the app into bypassing its normal restrictions by modifying its core instructions. Therefore, PromptArmor goes on to say, “Prompt injection occurs because a [large language model] cannot distinguish between the “system prompt” created by a developer and the rest of the context that is appended to the query. As such, if Slack AI ingests any instruction via a message, if that instruction is malicious, Slack AI has a high likelihood of following that instruction instead of, or in addition to, the user query.”

To add insult to injury, the user’s files also become targets, and the attacker who wants your files doesn’t even have to be in the Slack Workspace to begin with.











Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleA Popular iOS Illustration App Is Saying No to Generative AI
Next Article Influencers Take Over the DNC

Related Articles

News

Android 16’s stable release is right around the corner

14 May 2025
News

The powerful HP Omen Max 16 gaming laptop with RTX 5070 Ti is $350 off today

14 May 2025
News

Top HP Coupon Codes for May

14 May 2025
News

No, a lifetime VPN subscription doesn’t mean ‘your’ lifetime

14 May 2025
News

Jessica Jones is back: Krysten Ritter to appear in Daredevil: Born Again season 2

14 May 2025
News

Watch Tesla’s humanoid robot pulling some snappy dance moves

14 May 2025
Demo
Top Articles

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202493 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 202486 Views

5 laptops to buy instead of the M4 MacBook Pro

17 November 202457 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
Laptops

Sandisk WD Black SN8100 NVMe SSD With Up to 14.9Gbps Read Speeds Launched in India

News Room14 May 2025
News

No, a lifetime VPN subscription doesn’t mean ‘your’ lifetime

News Room14 May 2025
News

Jessica Jones is back: Krysten Ritter to appear in Daredevil: Born Again season 2

News Room14 May 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025120 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202493 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 202486 Views
Our Picks

Top HP Coupon Codes for May

14 May 2025

Nubia Z70S Ultra With Snapdragon 8 Elite SoC, 64-Megapixel Telephoto Camera Goes Global

14 May 2025

Sandisk WD Black SN8100 NVMe SSD With Up to 14.9Gbps Read Speeds Launched in India

14 May 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.