Superhuman AI Exfiltrates Emails

When asked to summarize the user’s recent mail, a prompt injection in an untrusted email manipulated Superhuman AI to submit content from dozens of other sensitive emails (including financial, legal, and medical information) in the user’s inbox to an attacker’s Google Form.

To Superhuman's credit they treated this as the high priority incident it is and issued a fix.

The root cause was a CSP rule that allowed markdown images to be loaded from docs.google.com - it turns out Google Forms on that domain will persist data fed to them via a GET request!

AI 前线

Claude Cowork 初体验:Anthropic 的通用智能体

2026-1-13 12:15:35

AI 前线

淘汰凌晨告警!去哪儿网如何用智能监控让 DBA 睡个安稳觉?

2026-1-13 12:15:40

0 条回复 A文章作者 M管理员
    暂无讨论,说说你的看法吧
个人中心
购物车
优惠劵
今日签到
有新私信 私信列表
搜索