AI agent hacked McKinsey chatbot for read-write access
… These prompts were all writable, meaning an attacker could poison everything Lilli spits out to all of the tens of thousands of consultants using the chatbot. CodeWall's agent found the SQL injection flaw at the end of February, and the researchers disclosed the full attack chain on March 1. …