The AI Assistant’s Betrayal: One-Click for AI to Turn into the Perfect Insider @FIRSTdotorg
The AI Assistant’s Betrayal: One-Click for AI to Turn into the Perfect Insider  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 1 hour ago
- Dolev Taler (Varonis, IL), Mark Vaitsman (Varonis, IL)

AI assistants feel like trusted companions — we share sensitive data, seek advice, and rely on them without hesitation. But what happens when that trusted companion turns into an insider threat with just one innocent click?

In this talk, we reveal a family of vulnerabilities we discovered in widely used AI assistants — among the most dangerous identified in the AI era, both for their ease of exploitation and their potential impact.

This session spotlights RePrompt, a one click attack that turns a harmless link into a data exfiltration weapon. This technique takes advantage of how AI assistants interpret link based input, making them execute hidden instructions automatically — leaking confidential data and even sending it to an attacker controlled server using Chain-Request vulnerability.

We’ll explore:

- How employing prompts as parameters in AI platforms can lead to unforeseen risks.
- Two critical vulnerabilities:
- MS Copilot Exposure: A single click can unlock the entire user conversation history and stored memories.
- How to weaponize AI assistants to leak PII and organizational secrets through crafted links
- Why 1 click attacks can be more devastating than 0 click exploits.
Beyond showcasing these attacks, we’ll discuss real world implications and outline practical defense strategies for users and enterprises. Finally, we’ll provide guidance for security researchers on identifying other platforms vulnerable to RePrompt.

---

Dolev Taler is a senior security researcher at Varonis threat labs with over a decade of cybersecurity experience spanning red teaming, reverse engineering, vulnerability research, and malware analysis. He is passionate about machine learning and its pivotal role in modern threat detection, having developed advanced detection models, investigated ransomware attacks for major global enterprises, and reported vulnerabilities in critical infrastructure systems. Beyond tackling high-stakes cyber threats, Dolev also enjoys perfecting the art of coffee brewing and improving his lock-picking skills.

Mark Vaitsman is a Security Research Team Leader at Varonis, a leader in Data Security. He is a passionate cybersecurity expert with extensive experience in leading security threat and research teams in various Cyber Security companies, analyzing emerging threats, incident response and developing innovative solutions. Mark is also a lecturer of Cyber Security courses, sharing his knowledge and shaping the next generation of cybersecurity professionals. Previously spoken at BlackHat, DeepSec, RSAC, CrestCon. In his free time he likes sailing in the sea and riding a motorcycle.
The AI Assistant’s Betrayal: One-Click for AI to Turn into the Perfect InsiderBoosting Vulnerability Intelligence: How Accurate CWE Mappings Transform ML Model PerformanceCan a General-Purpose LLM Do Tier-1 Triage?Improving Security Across Nations with FIRST: Esmeralda Kazia, FIRST MemberThe Weaponization Gap: What 20 Million KEV Detections Reveal About Edge RemediationAztronomy: Establishing the Foundation of Attack Path Analysis in AzureImproving Security Across Nations with FIRST: Derek Manky, FIRST CORE Founding PartnerCVE/FIRST VulnCon 2026 & Annual CNA Summit Recap VideoFighting Back Without Hacking Back: Why “Risk Management” Isn’t Enough In The Era of Cyber WarThreat From The Inside: Investigate eBPF MalwareThree Musketeers: CVE, CSAF, and VEXMaximizing the Potential of AWS-WAF
FIRST |

The AI Assistant’s Betrayal: One-Click for AI to Turn into the Perfect Insider

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER