Workhorse_ebooks ๐
Marketers promote AI-assisted developer tools as workhorses that are essential for today’s software engineer.
Developer platform GitLab, for instance, claims its Duo chatbot can “instantly generate a to-do list” that eliminates the burden of “wading through weeks of commits.”
Researchers from security firm Legit on Thursday demonstrated an attack that induced Duo into inserting malicious code into a script it had been instructed to write.
The attack could also leak private code and confidential issue data, such as zero-day vulnerability details.
All that’s required is for the user to instruct the chatbot to interact with a merge request or similar content from an outside source.
Comments
Post a Comment
Empathy recommended