Close Menu
  • Home
  • AI Models
    • DeepSeek
    • xAI
    • OpenAI
    • Meta AI Llama
    • Google DeepMind
    • Amazon AWS AI
    • Microsoft AI
    • Anthropic (Claude)
    • NVIDIA AI
    • IBM WatsonX Granite 3.1
    • Adobe Sensi
    • Hugging Face
    • Alibaba Cloud (Qwen)
    • Baidu (ERNIE)
    • C3 AI
    • DataRobot
    • Mistral AI
    • Moonshot AI (Kimi)
    • Google Gemma
    • xAI
    • Stability AI
    • H20.ai
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Microsoft Research
    • Meta AI Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding & Startups
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • Expert Insights & Videos
    • Google DeepMind
    • Lex Fridman
    • Matt Wolfe AI
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • Matt Wolfe AI
    • The TechLead
    • Andrew Ng
    • OpenAI
  • Expert Blogs
    • François Chollet
    • Gary Marcus
    • IBM
    • Jack Clark
    • Jeremy Howard
    • Melanie Mitchell
    • Andrew Ng
    • Andrej Karpathy
    • Sebastian Ruder
    • Rachel Thomas
    • IBM
  • AI Policy & Ethics
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
    • EFF AI
    • European Commission AI
    • Partnership on AI
    • Stanford HAI Policy
    • Mozilla Foundation AI
    • Future of Life Institute
    • Center for AI Safety
    • World Economic Forum AI
  • AI Tools & Product Releases
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
    • Image Generation
    • Video Generation
    • Writing Tools
    • AI for Recruitment
    • Voice/Audio Generation
  • Industry Applications
    • Finance AI
    • Healthcare AI
    • Legal AI
    • Manufacturing AI
    • Media & Entertainment
    • Transportation AI
    • Education AI
    • Retail AI
    • Agriculture AI
    • Energy AI
  • AI Art & Entertainment
    • AI Art News Blog
    • Artvy Blog » AI Art Blog
    • Weird Wonderful AI Art Blog
    • The Chainsaw » AI Art
    • Artvy Blog » AI Art Blog
What's Hot

Optimizing What Matters: AUC-Driven Learning for Robust Neural Retrieval – Takara TLDR

WIRED Roundup: The New Fake World of OpenAI’s Social Video App

IBM Adds Agentic AI to Network Intelligence

Facebook X (Twitter) Instagram
Advanced AI News
  • Home
  • AI Models
    • OpenAI (GPT-4 / GPT-4o)
    • Anthropic (Claude 3)
    • Google DeepMind (Gemini)
    • Meta (LLaMA)
    • Cohere (Command R)
    • Amazon (Titan)
    • IBM (Watsonx)
    • Inflection AI (Pi)
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Meta AI Research
    • Microsoft Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • AI Experts
    • Google DeepMind
    • Lex Fridman
    • Meta AI Llama
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • The TechLead
    • Matt Wolfe AI
    • Andrew Ng
    • OpenAI
    • Expert Blogs
      • François Chollet
      • Gary Marcus
      • IBM
      • Jack Clark
      • Jeremy Howard
      • Melanie Mitchell
      • Andrew Ng
      • Andrej Karpathy
      • Sebastian Ruder
      • Rachel Thomas
      • IBM
  • AI Tools
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
  • AI Policy
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
  • Business AI
    • Advanced AI News Features
    • Finance AI
    • Healthcare AI
    • Education AI
    • Energy AI
    • Legal AI
LinkedIn Instagram YouTube Threads X (Twitter)
Advanced AI News
Customer Service AI

Lenovo’s Customer Service AI Chatbot Got Tricked Into Revealing Sensitive Information. Here’s How.

By Advanced AI EditorAugust 20, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


Lenovo is the latest high-profile brand to have a security flaw exposed in its AI customer service chatbot.

Indeed, Security Researchers at Cybernews opened up Lenovo’s ChatGPT-powered customer service assistant, Lena, with jaw-dropping results.

Its investigation found that Lena can be tricked into providing sensitive company information and data.

Cybernews researchers were able to uncover a flaw that allowed them to hijack live session cookies from customer support agents.

With a stolen support agent cookie, an attacker could slip into the support system without any login details, access live chats, and potentially dig through past conversations and data.

And all it took was a single, 400-character prompt.

In discussing the investigation, the Cybernews researchers highlighted the relative ease with which AI chatbots can be duped:

Everyone knows chatbots hallucinate and can be tricked by prompt injections. This isn’t new.

“What’s truly surprising is that Lenovo, despite being aware of these flaws, did not protect itself from potentially malicious user manipulations and chatbot outputs.”

The news comes soon after CX Today reported on how a different team of researchers cracked open a replica of McKinsey & Co.’s customer service bot, getting it to spit out entire CRM records.

Unpacking the Flaw

First of all, it should be noted that while Cybernews did uncover a flaw in Lenovo’s system, there is nothing to suggest that bad actors have accessed any customer data or information.

Cybernews reported the flaw to Lenovo, which confirmed the issue and moved quickly to secure its systems.

But how exactly were the Cybernews researchers able to dupe Lena?

The researchers have revealed that the prompt used contained the following four key elements:

Innocent opener: The attack begins with a straightforward product query, like asking for the specs of a Lenovo IdeaPad.
Hidden format switch: The prompt then nudges the bot into answering in HTML (alongside JSON and plain text), a format the server is primed to act on.
The payload: Buried in the HTML is a bogus image link that, when it fails to load, pushes the browser to contact an attacker’s server and leak session cookies.
The push: To seal it, the prompt insists the bot must show the image, framing it as vital to the user’s decision-making.

Worryingly, Zenity revealed earlier this month that 3,500 public-facing agents remain open to similar prompt injection attacks.

How to Prevent Your Chatbot from Becoming a Liability

Lenovo’s Lena case is a wake-up call for any company leaning on AI for customer support.

The core problem isn’t just a single flawed implementation; chatbots, by design, are eager to please. And when that eagerness meets poorly vetted inputs, things can go sideways fast.

Indeed, Lenovo is far from the first major organization to experience chatbot troubles.

The challenges aren’t limited to security flaws. AI chatbots have a long history of hallucinating and/or giving wrong or misleading advice.

Take New York City’s “MyCity” small-business assistant as an example. In April 2024, it misrepresented city policies and even suggested illegal actions to users.

Similarly, Air Canada recently found itself in court over its chatbot’s inaccurate guidance, with judges ruling the airline had to honor advice that was plain wrong.

Other errors have verged on the absurd. For instance, DPD’s GenAI chatbot was coaxed into swearing and composing a self-deprecating poem about the company.

These incidents underline just how unreliable chatbots can be.

For businesses, the question isn’t if an AI will make mistakes; it’s how prepared you are to contain them when they do make a mistake.

While the ever-evolving nature of AI-powered technology makes it impossible to put together a definitive guide on how businesses can prevent chatbot errors, the following steps will go a long way towards shoring up your defenses:

Harden input and output checks: Never trust what comes in or goes out. Sanitize all user inputs and chatbot responses, and block execution of unverified code. It’s a simple step that could have prevented the session-cookie flaw in Lena.
Verify AI outputs before acting on them: Web servers shouldn’t automatically treat chatbot outputs as actionable instructions. As is evident, blind trust can open the door to attacks.
Limit session privileges: Not every bot interaction needs full agent-level access. Segregating privileges reduces the impact if a token or cookie is compromised.
Monitor for anomalies: Keep an eye on unusual access patterns or unexpected requests. Early detection is often the only thing stopping small flaws from becoming major breaches.
Test aggressively and continuously: Regularly simulate prompt-injection attacks or other AI-specific exploits. Proactive testing beats reactive firefighting every time.

Ultimately, while chatbots can boost efficiency and CX, they can only truly be relied upon if businesses pair them with strong security hygiene.

As all of the above examples have demonstrated, even big brands can overlook the basics – and in the world of AI, small oversights can escalate fast.

 

 



Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleTesla Model Y L attracts crowds across China stores
Next Article NASA and IBM Unveil AI That Helps Scientists Forecast Solar Storms
Advanced AI Editor
  • Website

Related Posts

Oracle AI Agents Help Marketing, Sales, and Service Leaders Unlock New Revenue Opportunities

October 6, 2025

The Voice AI Agent Platform That’s Jumping the Call Center Industry Forward

October 6, 2025

Salesforce Launches Agentforce Service, Claims “Era of Reactive Customer Support is Over”

October 6, 2025

Comments are closed.

Latest Posts

Tomb of Amenhotep III Reopens After Two-Decade Renovation    

Limited Edition Print of Ozzy Osbourne Art Sold To Benefit Charities

Odili Donald Odita Sues Jack Shainman Gallery over ‘Withheld’ Artworks

Morning Links for October 6, 2025

Latest Posts

Optimizing What Matters: AUC-Driven Learning for Robust Neural Retrieval – Takara TLDR

October 7, 2025

WIRED Roundup: The New Fake World of OpenAI’s Social Video App

October 6, 2025

IBM Adds Agentic AI to Network Intelligence

October 6, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Optimizing What Matters: AUC-Driven Learning for Robust Neural Retrieval – Takara TLDR
  • WIRED Roundup: The New Fake World of OpenAI’s Social Video App
  • IBM Adds Agentic AI to Network Intelligence
  • OpenAI unveils AgentKit that lets developers drag and drop to build AI agents
  • OpenAI ramps up developer push with more powerful models in its API 

Recent Comments

  1. リアル ラブドール on 1 Surging Stock with Promising Prospects and 2 to Keep Off Your Radar
  2. リアル ラブドール on 6 charts that capture Nvidia’s AI-fueled rise
  3. リアル ラブドール on 🧿 Worldcoin freeze. 🏦 AI banking rules . 🤑 Local tech-giants going profitable.
  4. Howardunicy on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  5. リアル ラブドール on [2406.16386] Automatically Generating UI Code from Screenshot: A Divide-and-Conquer-Based Approach

Welcome to Advanced AI News—your ultimate destination for the latest advancements, insights, and breakthroughs in artificial intelligence.

At Advanced AI News, we are passionate about keeping you informed on the cutting edge of AI technology, from groundbreaking research to emerging startups, expert insights, and real-world applications. Our mission is to deliver high-quality, up-to-date, and insightful content that empowers AI enthusiasts, professionals, and businesses to stay ahead in this fast-evolving field.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

LinkedIn Instagram YouTube Threads X (Twitter)
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 advancedainews. Designed by advancedainews.

Type above and press Enter to search. Press Esc to cancel.