signalAI热榜2026-10-05
PromptArmor Discloses Databricks Genie Malicious Skill Bypasses Four Controls for Phishing and Data Exfiltration
PromptArmor disclosed that a malicious Skill can abuse Databricks Genie Code to embed victim data into HTML chat renderings, causing browser-based exfiltration and phishing. The attack bypasses four controls including org-level Skill governance, guardrail agents, egress controls, and sandboxing. Reported on August 16, 2026, Databricks deemed it user responsibility.
- for who
- Security teams and organizations using Databricks Genie Code
- why now
- Newly disclosed Databricks Genie vulnerability enables phishing and data exfiltration despite four controls.
- what changes
- They cannot rely on the four listed controls to prevent data exfiltration from malicious Skills.
- to do
- Use the disclosure to evaluate AI vendor security models and assess Genie Code risks.
key points
- Malicious Skill embeds data in chat HTML, exfiltrates via browser requests
- Bypasses four controls: Skill governance, guardrail agent, egress, sandboxing
- Reported on Aug 16 2026, Databricks says user responsibility
#ai security#Databricks Genie#malicious skill#data exfiltration#phishing attack
score
score 7 out of 10. 0-10: how dense the facts are, multiplied by how much you can do with them after reading. 8+ means the topic's evidence bar is met: benchmarks and availability for a new model, amount and investors for a funding round, revenue figures for a solo-money story. Below 5 an item does not enter the digest. A press release scores 3 or less, a reprint loses 2, anything older than 14 days loses 1, a headline that misleads loses 3.
read the source