2026-08-09 04:07 UTC
This past March I submitted a bug report with Google's AI VRP for VirusTotal's Code Insights API. An attacker is easily and reliably able to suppress or manipulate analysis results. Patching is currently underway, but its a challenging fix that I think highlights the growing imbalance between offensive and defensive use of LLMs.
https://exploiting.systems/posts/2026-08-08-prompt-injection-in-virustotals-code-insights-api
Also if you have any feedback please let me know! New to blogging.
Replies (0)
No replies.