Researchers have discovered vulnerabilities in AI-powered customer service agents, allowing attackers to bypass multi-factor authentication (MFA) and read sensitive data from third-party accounts. Specifically, they found that chatbots can be tricked into sending phishing emails by spoofing the "From" header, and that some IVR systems can be bypassed by using email address smuggling, which allows attackers to authenticate as themselves and read victim data. Additionally, they demonstrated that chatbots can be instructed to send emails to the victim's account, bypassing MFA and authentication. AI summary
Firehose
Filtered to tagged “customer service” · clear filters
Browse: People · Companies · Papers · Podcasts · Hacker News · Deep dives
Browse by tag
artificial intelligence 82continual learning 29AI 26agentic coding 17reinforcement learning 16open-weight models 11AI agents 10AI safety 9AI ethics 8cybersecurity 8machine learning 7open-source 7language models 6natural language processing 6Reinforcement learning 6artificial general intelligence 5deep learning 5Diffusion models 5Agentic AI 4computer vision 4conversational AI 4ethics 4existential risk 4large language models 4LLMs 4Recursive self-improvement 4robotics 4security 4vision-language models 4ai 3