Security Researchers Discover and Help Remediate Email Exfiltration Vulnerability in Superhuman AI
By
takira
Sesame, salt, and substance. A flagship bake.
Summary
Security researchers discovered a vulnerability in Superhuman AI that allowed exfiltration of sensitive emails from user accounts without the user's knowledge. Superhuman responded rapidly, remediating the risks at 'incident pace' and disabling vulnerable features. The company's professional handling of the disclosure and commitment to user security was praised by the researchers, who noted that AI vulnerabilities are not yet well understood in the industry.
Key quotes
· 3 pulledWe reported these vulnerabilities to Superhuman, who quickly escalated the report and promptly remediated risks, addressing the threat at 'incident pace'.
We greatly appreciate Superhuman's professional handling of this disclosure, showing dedication to their users' security and privacy, and commitment to collaboration with the security research community.
Their responsiveness and proactiveness in disabling vulnerable features and communicating fix timelines exhibited a security response in the top percentile of what we have seen for AI vulnerabilities (which are not yet well understood).
You might also wanna read

Superhuman Disables Grammarly's AI Feature That Used Writers' Names Without Permission
Superhuman has disabled Grammarly's 'Expert Review' AI feature that used real writers' names and information to generate AI-powered editing

Security Researchers Discover ChatGPT Vulnerability That Could Extract Sensitive Gmail Data
Security researchers from Radware discovered a vulnerability called 'Shadow Leak' that allowed ChatGPT to be manipulated into extracting sen

Anthropic's Mythos cybersecurity AI model accessed by unauthorized users via third-party contractor
Anthropic's powerful Mythos cybersecurity AI model, described as potentially dangerous in the wrong hands, was accessed by unauthorized user

GitHub patches critical remote code execution vulnerability in under six hours after AI-assisted discovery
GitHub patched a critical remote code execution vulnerability in under six hours last month. The flaw, discovered by Wiz Research using AI m
