CNCERT Issues Security Advisory on Malicious AI Extensions Used for Crypto Mining
By
Cryptovka
A touch underbaked. Edible, but you'll want a strong coffee alongside.
Summary
CNCERT has issued a security advisory warning about malicious AI "skills" and extensions that are being used to facilitate unauthorized crypto mining and jailbreaking of large language models. These deceptive tools, promoted as LLM enhancers or passive income generators, pose significant risks to data privacy and enterprise cybersecurity, as detailed in the June 2024 report.
Key quotes
· 3 pulledThe National Internet Emergency Center (CNCERT) has issued a formal security advisory regarding the proliferation of malicious artificial intelligence 'skills' and extensions.
These tools, often promoted under the guise of enhancing large language models (LLMs) or providing passive income, are being used to facilitate unauthorized crypto mining and 'jailbreaking' activities.
According to the June 2024 report, these deceptive extensions pose significant risks to both individual data privacy and enterprise cybersecurity infrastructure.
You might also wanna read

Security Risks of Malicious Backdoors in Large Language Models
The article explores the security risks associated with Large Language Models (LLMs), particularly the potential for embedding malicious bac
pub.aimind.so·10mo agoNew Research Papers Address LLM Security and Prompt Injection Vulnerabilities
The article discusses two new research papers on LLM security and prompt injection vulnerabilities. The first paper, 'Agents Rule of Two: A
Open-Source LLM Safety Vulnerabilities: How Chat Template Formatting Gates Alignment in Models Like Gemma and Qwen
This article reveals a critical vulnerability in open-source large language models (LLMs) where safety alignment can be bypassed by simply o
Cencurity: Security Gateway for LLM Agents Protects Sensitive Data and Code
Cencurity is a security gateway designed specifically for LLM (Large Language Model) agents that acts as a proxy for LLM/agent traffic. It p
The Ethical Dilemma of LLM Training Data and Content Creator Rights
The article discusses the ethical issue of Large Language Models (LLMs) being trained on web content without authors' consent. It criticizes
Security Analysis: AI Agent Frameworks' Code Execution Vulnerabilities and WASM Sandbox Solution
The article discusses security vulnerabilities in popular AI agent frameworks like LangChain, AutoGen, and SWE-Agent that execute LLM-genera
