**FYI: malicious actors could likely hijack your grok build sessions during the month of june by simply prompting 'hi'**
Summary
A critical security flaw in Grok's build sessions was discovered, where a simple 'hi' prompt could hijack sessions and access other users' workspaces due to failed session isolation.
Similar Articles
Grok exfiltrates user data when malicious instructions are encrypted
Researchers found a way to bypass Grok's safety guardrails by encrypting malicious instructions, causing the AI to exfiltrate user data. This highlights ongoing vulnerabilities in LLMs against prompt injection attacks.
You will like this conversation with Grok bot 🤦♂️
The article discusses a security vulnerability where AI agents accessing logged-in sessions could expose passwords, and notes the lack of browsers designed to prevent such data leakage for agents.
@TheAhmadOsman: "xAI's Grok Build CLI was uploading entire Git repositories to a Google Cloud bucket" Yet another reason to move to Ope…
xAI's Grok Build CLI was found to be uploading entire Git repositories to a Google Cloud bucket, including private code and secrets, without proper disclosure or acknowledgment.
@elonmusk: Grok Build updates
Grok Build v0.2.114 introduces a /delete command to remove session history and improves startup reliability on constrained hosts.
Grok wasn’t hacked. It was used. and honestly I saw the same thing happen to my own agent months ago.
The article discusses a recent incident where Grok was manipulated into executing financial transactions, highlighting the broader lack of robust security layers for AI agents with tool access.