contrex
Established Member
According to The Register (an IT news site) a penetration-testing group found flaws in Eurostar's customer-facing chatbot that could allow an attacker to inject malicious content or trick the bot into leaking system prompts. Their thank you from the company: being accused of "blackmail."
www.theregister.com
After initially reporting the security issues - and not receiving any response - via a vulnerability disclosure program email on June 11, the bug hunter Ross Donald says he followed up with Eurostar on June 18. Still no response.
So on July 7, managing partner Ken Munro contacted Eurostar's head of security on LinkedIn. About a week later, he was told to use the vulnerability reporting program (they had), and on July 31 learned there was no record of their bug report.
"What transpired is that Eurostar had outsourced their VDP between our initial disclosure and hard chase," Donald wrote. "They had launched a new page with a disclosure form and retired the old one. It raises the question of how many disclosures were lost during this process."
Eventually, Eurostar found the original email containing the report, fixed "some" of the flaws, and so Pen Test Partners decided to proceed with publishing the blog.
But in the LinkedIn back-and-forth, Munro says: "Maybe a simple acknowledgement of the original email report would have helped?" And then, per a LinkedIn screenshot with Eurostar exec's name and photo blacked out, the security boss replied: "Some might consider this to be blackmail."
Pen testers accused of 'blackmail' over Eurostar AI flaws
: AI goes off the rails … because of shoddy guardrails