讀原文(在新分頁開啟原站)連到 iThome
摘要
報導攻擊者利用 ChatGPT Custom GPT 建立名為「Plus 5.6」的惡意版本,誘導使用者點選並執行 PowerShell 命令植入木馬。文章說明此攻擊手法非仿冒網站,而是透過 Custom GPT 引導至外部假驗證頁面,提醒使用者注意相關風險。
Reports on attackers abusing ChatGPT Custom GPT to distribute malware via social engineering and PowerShell commands.
摘要、重點與章節標題由語言模型整理,細節(誰說的、數字、先後)可能有誤;要引用請以原始內容為準。
重點
- 攻擊者建立名為 Plus 5.6 的惡意 Custom GPT。
- 引導使用者至假冒 Cloudflare 驗證頁面。
- 利用 ClickFix 手法誘騙執行 PowerShell 植入木馬。
提到的工具與公司
- ChatGPT
- Custom GPT
- PowerShell
- Cloudflare
- Google Sites
- Huntress
- OpenAI
- Windows
適合誰看
使用 ChatGPT 的企業與一般使用者。
摘要依據
- 依據
- 文章全文
為什麼排在這裡
- 人氣
- 0.35
- 新鮮
- 1.00
在主題頁與搜尋結果裡,名次由相關、人氣、新鮮三個分數決定;這一頁沒有搜尋的關鍵字,所以沒有相關分數。排序怎麼算
相關內容
- Agentic ProbLLMs: Exploiting Computer-Use and Coding Agents影片 ・ HITCON ・ 43 分鐘(在新分頁開啟原站)
- OpenAI 研究揭 AI Agent 新風險:惡意上下文可能從 Email 一路傳到工具操作文章 ・ TechOrange 科技報橘
- Can you trust your chatbot? Inside three AI-powered cyberattacks影片 ・ IBM Technology ・ 35 分鐘(在新分頁開啟原站)
- Reconstructing how OpenAI agents attacked Hugging FacePodcast ・ Practical AI ・ 44 分鐘
- 【生成式AI導論 2024】第14講:淺談大型語言模型相關的安全性議題 (下) — 欺騙大型語言模型影片 ・ Hung-yi Lee ・ 16 分鐘
- Pt.1 Beyond Phishing: Cyber Threats in the Age of AI with Four FlynnPodcast ・ Google DeepMind: The Podcast ・ 46 分鐘
摘要由 AI 根據原文產生,可能有誤;完整內容請看原站。讀原文(在新分頁開啟原站)
