frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Hidden risk in Notion 3.0 AI agents: Web search tool abuse for data exfiltration

https://www.codeintegrity.ai/blog/notion
57•abirag•2h ago

Comments

greyadept•2h ago
Here’s the link to the article: https://www.codeintegrity.ai/blog/notion
simonw•2h ago
Yeah that's a better link. I have some notes on my blog too: https://simonwillison.net/2025/Sep/19/notion-lethal-trifecta...
gnabgib•1h ago
https://news.ycombinator.com/item?id=45303966

Oh I see someone's updated the URL so now this is just a dupe of that submission (it was formerly linked to a tweet)

nwellinghoff•1h ago
How does a random user get a document in your notion instance?
cobertos•1h ago
People put all kinds of stuff in Notion. People use it as a DB. People catalog things they find online (web clipper). There's collaboration features.

There are many ways

Lalabadie•1h ago
The article gives a PDF document as an example, but depending on how links are opened and stored for Notion agents, threat actors could serve a different web page depending on the crawler/browser agent.

That means any industry-known documentation that seems good for bookmarking can be a good target.

memothon•8m ago
Lots of companies have automations with Zapier etc. to upload things like invoices or other documents directly to notion. Or someone gets emailed a document with an exploit and they upload it.
lacoolj•1h ago
This attack was demonstrated a couple years ago, it's not really a new thing.

https://simonwillison.net/2023/Oct/14/multi-modal-prompt-inj...

tadfisher•52m ago
Is anyone working on the instruction/data-conflation problem? We're extremely premature in hooking up LLMs to real data sources and external functions if we can't keep them from following instructions in the data. Notion in particular shows absolutely zero warnings to end users, and encourages them to connect GitHub, GMail, Jira, etc. to the model. At this point it's basically criminal to treat this as a feature of a secure product.
abirag•40m ago
Hey, I’m the author of this exploit. At CodeIntegrity.ai, we’ve built a platform that visualizes each of the control flows and data flows of an agentic AI system connected to tools to accurately assess each of the risks. We also provide runtime guardrails that give control over each of these flows based on your risk tolerance.

Feel free to email me at abi@codeintegrity.ai — happy to share more

chanw•33m ago
This was a great article, because it demonstrated the vuln in a practical way and wasn't overly technical either. Thanks for sharing

Less is safer: how Obsidian reduces the risk of supply chain attacks

https://obsidian.md/blog/less-is-safer/
79•saeedesmaili•2h ago•49 comments

Hidden risk in Notion 3.0 AI agents: Web search tool abuse for data exfiltration

https://www.codeintegrity.ai/blog/notion
57•abirag•2h ago•11 comments

Show HN: Zedis – A Redis clone I'm writing in Zig

https://github.com/barddoo/zedis
40•barddoo•2h ago•15 comments

Feedmaker: URL + CSS selectors = RSS feed

https://feedmaker.fly.dev
63•mustaphah•3h ago•14 comments

Xmonad seeking help for Wayland port

https://xmonad.org/news/2023/10/06/wayland.html
28•clircle•2d ago•15 comments

Show HN: WeUseElixir - Elixir project directory

https://weuseelixir.com/
72•taddgiles•4h ago•11 comments

Starfront Observatories

https://starfront.space/
7•stefanpie•2d ago•1 comments

Ants that seem to defy biology – They lay eggs that hatch into another species

https://www.smithsonianmag.com/smart-news/these-ant-queens-seem-to-defy-biology-they-lay-eggs-tha...
309•sampo•12h ago•98 comments

Tonemaps

https://mini.gmshaders.com/p/tonemaps
23•bpierre•2d ago•2 comments

An untidy history of AI across four books

https://hedgehogreview.com/issues/lessons-of-babel/articles/perplexity
80•ewf•6h ago•26 comments

Three-Minute Take-Home Test May Identify Symptoms Linked to Alzheimer's Disease

https://www.smithsonianmag.com/smart-news/three-minute-take-home-test-may-identify-symptoms-linke...
50•pseudolus•5h ago•10 comments

Internet Archive's big battle with music publishers ends in settlement

https://arstechnica.com/tech-policy/2025/09/internet-archives-big-battle-with-music-publishers-en...
258•coloneltcb•4d ago•108 comments

R MCP Server

https://github.com/finite-sample/rmcp
69•neehao•3d ago•7 comments

Ruby Central's Attack on RubyGems [pdf]

https://pup-e.com/goodbye-rubygems.pdf
586•jolux•16h ago•190 comments

Your very own humane interface: Try Jef Raskin's ideas at home

https://arstechnica.com/gadgets/2025/09/your-very-own-humane-interface-try-jef-raskins-ideas-at-h...
57•zdw•6h ago•9 comments

Time Spent on Hardening

https://third-bit.com/2025/09/18/time-spent-on-hardening/
39•mooreds•4h ago•15 comments

The Economic Impacts of AI: A Multidisciplinary, Multibook Review [pdf]

https://kevinbryanecon.com/BryanAIBookReview.pdf
38•cjbarber•4h ago•11 comments

Restriction on Entry of Certain Nonimmigrant Workers

https://www.whitehouse.gov/presidential-actions/2025/09/restriction-on-entry-of-certain-nonimmigr...
32•quantumwannabe•1h ago•24 comments

Kernel: Introduce Multikernel Architecture Support

https://lwn.net/ml/all/20250918222607.186488-1-xiyou.wangcong@gmail.com/
104•ahlCVA•9h ago•24 comments

YouTube downloaders (and how Google silenced the press)

https://windowsread.me/p/best-youtube-downloaders
165•Leftium•12h ago•67 comments

How to waste CPU like a Professional

https://mostlynerdless.de/blog/2025/09/19/how-to-waste-cpu-like-a-professional/
28•tanelpoder•4h ago•8 comments

Show the Physics

https://interactivetextbooks.tudelft.nl/showthephysics/Introduction/About.html
134•pillars•3d ago•7 comments

Ask HN: Has anyone else been unemployed for over two years?

272•ncarlson•3h ago•262 comments

Revamping an Old TV as a Gift (2019)

https://blog.davidv.dev/posts/revamping-an-old-tv-as-a-gift/
57•deivid•9h ago•24 comments

Safepoints and Fil-C

https://fil-c.org/safepoints
64•matt_d•3d ago•29 comments

Shipping 100 hardware units in under eight weeks

https://farhanhossain.substack.com/p/how-we-shipped-100-hardware-units
100•M_farhan_h•1d ago•57 comments

The health benefits of sunlight may outweigh the risk of skin cancer

https://www.economist.com/science-and-technology/2025/09/17/the-health-benefits-of-sunlight-may-o...
189•petethomas•19h ago•177 comments

Nostr

https://nostr.com/
309•dtj1123•18h ago•269 comments

I regret building this $3000 Pi AI cluster

https://www.jeffgeerling.com/blog/2025/i-regret-building-3000-pi-ai-cluster
403•speckx•10h ago•297 comments

Dynamo AI (YC W22) Is Hiring a Senior Kubernetes Engineer

https://www.ycombinator.com/companies/dynamo-ai/jobs/fU1oC9q-senior-kubernetes-engineer
1•DynamoFL•12h ago