<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Exploits on Thomy Gölles</title><link>https://thomygoelles.com/tags/exploits/</link><description>Recent content in Exploits on Thomy Gölles</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 24 Aug 2025 12:05:53 +0000</lastBuildDate><atom:link href="https://thomygoelles.com/tags/exploits/index.xml" rel="self" type="application/rss+xml"/><item><title>Exploits and possible LLM attacks plus M365 Copilot</title><link>https://thomygoelles.com/exploits-and-possible-llm-attacks-plus-m365-copilot/</link><pubDate>Sun, 04 Feb 2024 12:26:38 +0000</pubDate><guid>https://thomygoelles.com/exploits-and-possible-llm-attacks-plus-m365-copilot/</guid><description>&lt;p&gt;There is a German idiom called &amp;ldquo;in between the years&amp;rdquo;, meaning the timeframe from Christmas to New Year&amp;rsquo;s eve. It is a time of reflection and of course family. This year it was also the time of the &lt;a href="https://events.ccc.de/congress/2023/infos/index.html" target="_blank" rel="noopener"&gt;37th Chaos Communication Congress (37C3) in Hamburg&lt;/a&gt;. The 37C3 was a hybrid event, meaning it was a physical event in Hamburg and a virtual event on the internet.&lt;/p&gt;
&lt;h2 id="real-world-exploits-and-mitigations-in-llm-applications"&gt;Real-world exploits and mitigations in LLM applications&lt;/h2&gt;
&lt;p&gt;One of the talks that I found very interesting was the talk about &lt;a href="https://www.youtube.com/watch?v=qyTSOSDEC5M" target="_blank" rel="noopener"&gt;Real-world exploits and mitigations in LLM applications (37c3)&lt;/a&gt;. The talk was about a new type of attacks that are based on LLMs by &lt;a href="https://www.linkedin.com/in/johannrehberger/" target="_blank" rel="noopener"&gt;Johann Rehberger&lt;/a&gt;. Johann is currently a Red Team Director at Electronic Arts and worked as a Principal Security Engineer Manager for years at Microsoft. Red Teams are tasked with simulating attacks on a company&amp;rsquo;s systems to test the effectiveness of its security measures. So it&amp;rsquo;s very interessting so see his thoughts on this topic.&lt;/p&gt;</description></item></channel></rss>