Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • This region in space poses the greatest danger in our Solar System
    • Practical info and special tips for the EU-Startups Summit 2026 in Malta – look inside!
    • Your Phone Notifications Reveal More Than You Realize. Here’s How to Lock Them Down
    • Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
    • iPad Pro M5 Review: Closer Than Ever to the Future Mac
    • How AI Policy in South Africa Is Ruining Itself
    • Dual iris laser projector offers theater blacks
    • The Startup World Cup is your chance to pitch in Silicon Valley and win $1.4 million
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Wednesday, April 29
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Researchers cause GitLab AI developer assistant to turn safe code malicious
    News

    Researchers cause GitLab AI developer assistant to turn safe code malicious

    Editor Times FeaturedBy Editor Times FeaturedMay 24, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    Entrepreneurs promote AI-assisted developer instruments as workhorses which might be important for in the present day’s software program engineer. Developer platform GitLab, as an example, claims its Duo chatbot can “immediately generate a to-do checklist” that eliminates the burden of “wading by means of weeks of commits.” What these corporations don’t say is that these instruments are, by temperament if not default, simply tricked by malicious actors into performing hostile actions in opposition to their customers.

    Researchers from safety agency Legit on Thursday demonstrated an assault that induced Duo into inserting malicious code right into a script it had been instructed to jot down. The assault may additionally leak non-public code and confidential concern knowledge, reminiscent of zero-day vulnerability particulars. All that’s required is for the consumer to instruct the chatbot to work together with a merge request or related content material from an outdoor supply.

    AI assistants’ double-edged blade

    The mechanism for triggering the assaults is, in fact, immediate injections. Among the many most typical types of chatbot exploits, immediate injections are embedded into content material a chatbot is requested to work with, reminiscent of an e mail to be answered, a calendar to seek the advice of, or a webpage to summarize. Giant language model-based assistants are so desperate to comply with directions that they’ll take orders from nearly anyplace, together with sources that may be managed by malicious actors.

    The assaults concentrating on Duo got here from varied sources which might be generally utilized by builders. Examples embody merge requests, commits, bug descriptions and feedback, and supply code. The researchers demonstrated how directions embedded inside these sources can lead Duo astray.

    “This vulnerability highlights the double-edged nature of AI assistants like GitLab Duo: when deeply built-in into improvement workflows, they inherit not simply context—however danger,” Legit researcher Omer Mayraz wrote. “By embedding hidden directions in seemingly innocent undertaking content material, we had been capable of manipulate Duo’s conduct, exfiltrate non-public supply code, and exhibit how AI responses may be leveraged for unintended and dangerous outcomes.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden

    April 29, 2026

    The European Commission issues preliminary DSA findings against Meta, saying Instagram and Facebook fail to prevent under-13 users from accessing the services (Gian Volpicelli/Bloomberg)

    April 29, 2026

    Alberta online gambling expansion sparks concern among First Nations casino operators

    April 29, 2026

    Better Markets urges courts to let states regulate prediction markets, not CFTC

    April 29, 2026

    Q&A with Sam Altman and AWS CEO Matt Garman about OpenAI’s new partnership with AWS, Bedrock Managed Agents, Trainium chips, and more (Ben Thompson/Stratechery)

    April 28, 2026

    Snapchat launches AI Sponsored Snaps, a conversational ad format in the Chat tab that lets users talk to brand-specific AI agents for product recommendations (Aisha Malik/TechCrunch)

    April 28, 2026

    Comments are closed.

    Editors Picks

    This region in space poses the greatest danger in our Solar System

    April 29, 2026

    Practical info and special tips for the EU-Startups Summit 2026 in Malta – look inside!

    April 29, 2026

    Your Phone Notifications Reveal More Than You Realize. Here’s How to Lock Them Down

    April 29, 2026

    Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden

    April 29, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Ducati unveils lighter, more powerful Hypermotard V2 and SP

    November 8, 2025

    Two arrested in Murfreesboro after police uncover illegal gambling operation

    July 30, 2025

    F1 2026: Everything to Know About Streaming on Apple TV This Season

    March 7, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.