Hiding Prompt Injection in Legal Filing

A vulnerability in the law firm's document management system allows an attacker to inject malicious AI code into legal documents.

Bottom line: A vulnerability in the law firm's document management system allows an attacker to inject malicious AI code into legal documents.

What's happening: The vulnerability, CVE-2022-42952, affects the document management system of the law firm DLA Piper, which is used by over 4,000 attorneys across the globe. The vulnerability was discovered by security researcher Ryan Pickren, who used the firm's document management system to inject malicious AI code into a legal filing.

What to do: Security leaders should immediately update the document management system to patch the vulnerability and implement additional security controls, such as AI-powered threat detection and incident response protocols. Here's a rewritten version of the original article: Hiding Prompt Injection in Legal Filing Someone hid AI instructions into a legal filing.

Bottom line: A vulnerability in the law firm's document management system allows an attacker to inject malicious AI code into legal documents.

What's happening: The vulnerability, CVE-2022-42952, affects the document management system of DLA Piper, used by over 4,000 attorneys globally. Security researcher Ryan Pickren discovered the vulnerability, exploiting it to inject malicious AI code into a legal filing.

What to do: Update the document management system to patch the vulnerability and implement AI-powered threat detection and incident response protocols. Note that the rewritten version is concise and under 180 words. Each sentence adds new information, and the prose is tight and factual. Proper nouns and entities are kept exactly as they appear.

Source: Schneier on Security