Close Menu
  • Home
  • AI Models
    • DeepSeek
    • xAI
    • OpenAI
    • Meta AI Llama
    • Google DeepMind
    • Amazon AWS AI
    • Microsoft AI
    • Anthropic (Claude)
    • NVIDIA AI
    • IBM WatsonX Granite 3.1
    • Adobe Sensi
    • Hugging Face
    • Alibaba Cloud (Qwen)
    • Baidu (ERNIE)
    • C3 AI
    • DataRobot
    • Mistral AI
    • Moonshot AI (Kimi)
    • Google Gemma
    • xAI
    • Stability AI
    • H20.ai
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Microsoft Research
    • Meta AI Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding & Startups
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • Expert Insights & Videos
    • Google DeepMind
    • Lex Fridman
    • Matt Wolfe AI
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • Matt Wolfe AI
    • The TechLead
    • Andrew Ng
    • OpenAI
  • Expert Blogs
    • François Chollet
    • Gary Marcus
    • IBM
    • Jack Clark
    • Jeremy Howard
    • Melanie Mitchell
    • Andrew Ng
    • Andrej Karpathy
    • Sebastian Ruder
    • Rachel Thomas
    • IBM
  • AI Policy & Ethics
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
    • EFF AI
    • European Commission AI
    • Partnership on AI
    • Stanford HAI Policy
    • Mozilla Foundation AI
    • Future of Life Institute
    • Center for AI Safety
    • World Economic Forum AI
  • AI Tools & Product Releases
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
    • Image Generation
    • Video Generation
    • Writing Tools
    • AI for Recruitment
    • Voice/Audio Generation
  • Industry Applications
    • Finance AI
    • Healthcare AI
    • Legal AI
    • Manufacturing AI
    • Media & Entertainment
    • Transportation AI
    • Education AI
    • Retail AI
    • Agriculture AI
    • Energy AI
  • AI Art & Entertainment
    • AI Art News Blog
    • Artvy Blog » AI Art Blog
    • Weird Wonderful AI Art Blog
    • The Chainsaw » AI Art
    • Artvy Blog » AI Art Blog
What's Hot

Grammarly Launches 8 AI Writing Tools: Citation Finder, AI Grader, Plagiarism Checker, Proofreader and More

LegalZoom To Offer Patent Filings Via Own Law Firm – Artificial Lawyer

Motion2Motion: Cross-topology Motion Transfer with Sparse Correspondence – Takara TLDR

Facebook X (Twitter) Instagram
Advanced AI News
  • Home
  • AI Models
    • OpenAI (GPT-4 / GPT-4o)
    • Anthropic (Claude 3)
    • Google DeepMind (Gemini)
    • Meta (LLaMA)
    • Cohere (Command R)
    • Amazon (Titan)
    • IBM (Watsonx)
    • Inflection AI (Pi)
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Meta AI Research
    • Microsoft Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • AI Experts
    • Google DeepMind
    • Lex Fridman
    • Meta AI Llama
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • The TechLead
    • Matt Wolfe AI
    • Andrew Ng
    • OpenAI
    • Expert Blogs
      • François Chollet
      • Gary Marcus
      • IBM
      • Jack Clark
      • Jeremy Howard
      • Melanie Mitchell
      • Andrew Ng
      • Andrej Karpathy
      • Sebastian Ruder
      • Rachel Thomas
      • IBM
  • AI Tools
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
  • AI Policy
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
  • Business AI
    • Advanced AI News Features
    • Finance AI
    • Healthcare AI
    • Education AI
    • Energy AI
    • Legal AI
LinkedIn Instagram YouTube Threads X (Twitter)
Advanced AI News
Customer Service AI

Lenovo’s Lena AI chatbot had weakness that let attackers hijack sessions

By Advanced AI EditorAugust 18, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


Lenovo’s customer service AI chatbot Lena was recently found to contain a critical vulnerability that could allow attackers to steal session cookies and run malicious code.

Cybernews researchers discovered that with just one maliciously crafted prompt, the AI could be manipulated into exposing sensitive data. Lenovo has since fixed the issue, but the case shows how chatbots can create fresh risks when not properly secured.

SEE ALSO: New AI-powered Operator X streamlines offline defensive cyber missions

The flaw involved cross-site scripting, an attack method that has existed for decades.

Researchers showed that Lena could be tricked into producing output containing malicious HTML. When a browser loaded that response, it could send private cookies to an attacker’s server. This allowed criminals to impersonate customer support agents or gain access to internal systems.

“People-pleasing is still the issue that haunts large language models (LLMs), to the extent that, in this case, Lena accepted our malicious payload, which produced the XSS vulnerability and allowed the capture of session cookies upon opening the conversation. Once you’re transferred to a real agent, you’re getting their session cookies as well,” said Cybernews researchers.

The attack chain was surprisingly simple. It began with a normal product query, such as a request for specifications. Hidden in the same prompt were instructions that forced Lena to format the answer in HTML. That HTML included an image request to a fake address. When the image failed to load, the browser sent all cookie data to the attacker’s server.

“Already, this could be an open gate to their customer support platform. But the flaw opens a trove of potential other security implications,” explained Cybernews researchers.

Those risks went far beyond cookie theft. Malicious scripts could alter what agents saw, capture keystrokes, redirect to phishing sites, or plant backdoors inside the network.

Once an attacker gained control of a support agent’s session, they could log in without needing usernames or passwords.

“Using the stolen support agent’s session cookie, it is possible to log into the customer support system with the support agent’s account without needing to know the email, username, or password for that account. Once logged in, an attacker could potentially access active chats with other users and possibly past conversations and data,” researchers warned.

Lenovo patches flaw

Lenovo responded quickly once informed. Cybernews confirmed that the flaw was responsibly disclosed and fixed before public release.

Still, experts argue the discovery is a lesson for the industry. “Everyone knows chatbots hallucinate and can be tricked by prompt injections. This isn’t new. What’s truly surprising is that Lenovo, despite being aware of these flaws, did not protect itself from potentially malicious user manipulations and chatbot outputs,” said the Cybernews Research team.

The root cause was weak sanitization. Lena accepted input without filtering, and its responses were not cleaned before being displayed.

“This isn’t just Lenovo’s problem. Any AI system without strict input and output controls creates an opening for attackers. LLMs don’t have an instinct for ‘safe’ — they follow instructions exactly as given. Without strong guardrails and continuous monitoring, even small oversights can turn into major security incidents,” said Žilvinas Girėnas, Head of Product at nexos.ai.

Cybernews researchers stressed that companies need to treat all chatbot interactions as untrusted. “The fundamental flaw is the lack of robust input and output sanitization and validation. It’s better to adopt a ‘never trust, always verify’ approach for all data flowing through the AI chatbot systems,” they said. [Girėnas added, “We approach every AI input and output as untrusted until it’s verified safe. That mindset helps block prompt injections and other risks before they reach critical systems. It’s about building security checks into the process so trust is earned, not assumed.”

What do you think about AI chatbots becoming a new target for old hacking tricks? Let us know in the comments.



Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleTalent compensation is not a cost
Next Article AI Video Tools, Security Enhancements
Advanced AI Editor
  • Website

Related Posts

AI Customer Service Falls Short of User Expectations: Verizon

August 19, 2025

AI agents evolve how automated customer service works

August 19, 2025

US vs. Japan in Customer Experience and AI

August 19, 2025

Comments are closed.

Latest Posts

Barbara Hepworth Sculpture Will Remain in UK After £3.8 M. Raised

After 12-Year Hiatus, Egypt’s Alexandria Biennale Will Return

Ai Weiwei Visits Ukraine’s Front Line Ahead of Kyiv Installation

Maren Hassinger to Receive Her Largest Retrospective to Date Next Year

Latest Posts

Grammarly Launches 8 AI Writing Tools: Citation Finder, AI Grader, Plagiarism Checker, Proofreader and More

August 20, 2025

LegalZoom To Offer Patent Filings Via Own Law Firm – Artificial Lawyer

August 20, 2025

Motion2Motion: Cross-topology Motion Transfer with Sparse Correspondence – Takara TLDR

August 20, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Grammarly Launches 8 AI Writing Tools: Citation Finder, AI Grader, Plagiarism Checker, Proofreader and More
  • LegalZoom To Offer Patent Filings Via Own Law Firm – Artificial Lawyer
  • Motion2Motion: Cross-topology Motion Transfer with Sparse Correspondence – Takara TLDR
  • DeepSeek’s V3.1 update and missing R1 label spark speculation over fate of R2 AI model
  • How Claude Code AI Handles 1 Million Tokens to Boost Efficiency

Recent Comments

  1. HowardGok on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  2. ChrisStits on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  3. Richardsmeap on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  4. JimmieSed on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  5. kinobay-346 on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10

Welcome to Advanced AI News—your ultimate destination for the latest advancements, insights, and breakthroughs in artificial intelligence.

At Advanced AI News, we are passionate about keeping you informed on the cutting edge of AI technology, from groundbreaking research to emerging startups, expert insights, and real-world applications. Our mission is to deliver high-quality, up-to-date, and insightful content that empowers AI enthusiasts, professionals, and businesses to stay ahead in this fast-evolving field.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

LinkedIn Instagram YouTube Threads X (Twitter)
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 advancedainews. Designed by advancedainews.

Type above and press Enter to search. Press Esc to cancel.