Simon Willison’s Weblog

Subscribe

Items tagged aws, ai in 2024

Filters: Year: 2024 × aws × ai × Sorted by date


AWS Fixes Data Exfiltration Attack Angle in Amazon Q for Business. An indirect prompt injection (where the AWS Q bot consumes malicious instructions) could result in Q outputting a markdown link to a malicious site that exfiltrated the previous chat history in a query string.

Amazon fixed it by preventing links from being output at all—apparently Microsoft 365 Chat uses the same mitigation. # 19th January 2024, 12:02 pm

Types

Years

Months

Tags