Shared Resource Poisoning

Type: technique

Description: The adversary entices the user or uses access by the AI system to create a resource with malicious instructions and share it widely within the organization. Variants include SharePoint and Google Drive documents accessible company-wide.

Version: 0.1.0

Created At: 2024-10-11 16:54:32 +0300

Last Modified At: 2024-10-11 16:54:32 +0300


External References

  • --> Lateral Movement (tactic): An adversary can infect threads by other uses by creating a company-wide shared resource indexes by the RAG system.
  • --> RAG Poisoning (technique): Shared Resource Poisoning is a form of RAG Poisoning, leveraging acquired intra-company access for lateral movement.