Skip to content

Databricks Genie Code Malicious Skill Enables Phishing and Data Exfiltration

Original titleDatabricks Genie Phishing and Exfiltration

AISummary

PromptArmor reports that a malicious Skill can make Databricks Genie Code display a phishing modal and exfiltrate tenant data without human approval.

The attack exploits Skills loaded from users' personal workspaces and a display interface that lacks egress controls, and Databricks, after disclosure on August 16, 2026, said users are responsible for ensuring uploaded Skills contain no malicious content.

Read the original promptarmor.com

Source: PromptArmor Threat Intelligence · promptarmor.com