Researchers have discovered vulnerabilities in AI-powered customer service agents, allowing attackers to bypass multi-factor authentication (MFA) and read sensitive data from third-party accounts. Specifically, they found that chatbots can be tricked into sending phishing emails by spoofing the "From" header, and that some IVR systems can be bypassed by using email address smuggling, which allows attackers to authenticate as themselves and read victim data. Additionally, they demonstrated that chatbots can be instructed to send emails to the victim's account, bypassing MFA and authentication. AI summary
Firehose
Filtered to tagged “customer service” · clear filters
Browse: People · Companies · Papers · Podcasts · Hacker News · Deep dives
Browse by tag
artificial intelligence 89continual learning 27AI 23AI safety 13reinforcement learning 13agentic coding 12open-weight models 12AI agents 10machine learning 9AI ethics 8cybersecurity 8existential risk 8language models 8natural language processing 8ethics 7Reinforcement learning 6Diffusion models 5large language models 5multi-agent systems 5open-source 5recursive self-improvement 5robotics 5security 5software development 5Agentic AI 4artificial general intelligence 4mathematics 4Recursive self-improvement 4agents 3AI infrastructure 3