At BlueHat Asia, researcher shows SQL Copilot prompt injection breaks read-only assumptions
wunderwuzzi23 · x · 2026-09-18
Security researcher Johann Rehberger presented at Microsoft's BlueHat Asia on AI assistants inheriting user privileges: SQL Copilot in SQL Server Management Studio becomes a powerful attack target when connected to highly privileged accounts. Live demos showed how "read-only" assumptions break down and prompt injection can steer AI behavior. Key message: security boundaries matter as much as model instructions.
More from Safety
- The overlooked risk in AI regulation: capture by militants, not just by firms — soumitrashukla9 · 2026-09-18
- Chris Rohlf: agents can't be deterred like humans — defense must move at machine speed — chrisrohlf · 2026-09-18
- Nathan Lambert: OpenAI hack via Claude shows closed models are the real AI risk tip — natolambert · 2026-09-18
- Researchers clash over whether training AI to disclaim consciousness makes models more misaligned — coherence · 2026-09-18
- Judea Pearl shares new causal inference papers while Congress debates AI regulation — yudapearl · 2026-09-18
- MIT Tech Review answers readers: could AI really kill us all? — nordicinst · 2026-09-18