Elektrine lite

← Feed

@neurovagrant@masto.deoan.org

Post #4242294

2026-07-30 12:07 UTC

@briankrebs@infosec.exchange I would love to see the raw body of the scam email to see if there was any attempt at prompt injection, or if it was literally just Gemini falling for a basic scam email.

Replies (3)

  • @jargoggles@kolektiva.social 2026-07-30 13:16

    @neurovagrant@masto.deoan.org @briankrebs@infosec.exchange I'm positive that any scammer worth their salt is baking in at least basic prompt injection. With just a little more text, agents will basically do their work for them. That kind of asymmetric effort:payoff ratio is what they live for.

    Open ##4242292

  • @osma@mas.to 2026-07-30 12:10

    Also: did it scan for messages in the spam folder too, because last I used Gmail (over a year ago, admittedly) it was pretty good about not letting spam/scam in the inbox. @neurovagrant@masto.deoan.org @briankrebs@infosec.exchange

    Open ##4247529

  • @neurovagrant@masto.deoan.org @briankrebs@infosec.exchange I have a custom setup to use gemma to apply simple labeling to one of my email inboxes. One of the big lessons I learned is that you can't assume the model will scrutinize anything on its own. This is my long winded way of saying that it might not even require prompt injection, or not very advanced prompt injection. It'll be interesting to get more details about this.

    Open ##4282775