There it is! Orange Tsai (@orange_8361) of DEVCORE Research Team was able to exploit Microsoft Exchange! If confirmed, they win a whooping $200,000 and 20 Master of Pwn points. Off to the disclosure room to explain how they did it and seal the deal. #Pwn2Own#P2OBerlin
@thedawgyg Found 5 IDORs on a public program, only reported 2 to test the waters, both marked as duplicates of a report that the endpoint was on a different domain and different code base. Shit like this encourages people to do the wrong thing.
Thread - My own opinion & this is to the Bug Hunters, What @Hacker0x01 is doing re AI, is essentially stealing “our work” “our research” for their own profitability. They are for sure breaking client agreements, wherein a clients data / vulns belong to the client. Not H1!!
@thedawgyg@CrazyVibes_1 the average cost of a pack of 20 cigarettes in Australia exceeds A$40, with prices often reaching over A$50 (approximately US$31.50)
Prompt Injection is one of the first attack vectors used to exploit weaknesses or bypass behavior in AI models.
Here is an illustrated thread with 5 different prompt injection techniques 👇