
AI Workflow Identity Hijacking Lets Attackers Steal Sensitive Data Without Prompt Injection
A newly disclosed AI security threat dubbed Workflow Identity Hijacking could let attackers extract sensitive enterprise data by submitting ordinary requests through public-facing channels such as support inboxes, web forms, GitHub issues, or shared documents. Unlike prompt injection attacks, the technique does not require adversaries to manipulate, jailbreak, or override a large language model’s instructions. […]
The post AI Workflow Identity Hijacking Lets Attackers Steal Sensitive Data Without Prompt Injection appeared first on Cyber Security News.