Elektrine lite

← Feed

ropbear

ropbear@infosec.exchange

Posts

  • View post

    This past March I submitted a bug report with Google's AI VRP for VirusTotal's Code Insights API. An attacker is easily and reliably able to suppress or manipulate analysis results. Patching is currently underway, but its a challenging fix that I think highlights the growing imbalance between offensive and defensive use of LLMs. https://exploiting.systems/posts/2026-08-08-prompt-injection-in-virustotals-code-insights-api Also if you have any feedback please let me know! New to blogging...