• News/
  • https://www.theregister.com/2025/05/01/amazon_red_teamed_alexaplus/

Amazon CISO: How AWS red-teamed Alexa+ AI assistant

The Register
·
Jessica Lyons
·
Published May 1, 2025
·
Updated

RSAC If Amazon's Alexa+ works as intended, it could show how an AI assistant helps with everyday tasks like making dinner reservations or arranging an oven repair. Or things could go terribly wrong: it might fire up the oven and turn dinner plans into a house fire. This is why the e-commerce giant brought in security engineers, including both red teams and penetration testers, to work alongside product developers from the beginning, according to Amazon CISO Amy Herzog. Their job was to anticipate what could go wrong and ensure safety and security guardrails were in place to prevent Alexa+ from jumping the track. "It's funny how, having been in both seats, the product engineer thinks about making the intended thing work, and the security engineer thinks about all the ways that you can game that system," Herzog told The Register on the outskirts of RSA Conference in San Francisco this week. "Whenever you're talking about a system that can take actions on behalf of someone our immediate [reaction is]: Wouldn't it be good if, like me, as someone who's running this household could just say, This is what I need to go shopping for. These are the dinner reservations I need to make. Go make that happen. Schedule a delivery window," she said. "And then my kid comes into the kitchen and says, and also 50 pepperoni pizzas for me and my friends." The product engineer thinks about making the intended thing work, and the security engineer thinks about all the ways that you can game that sys...

Read full article

Affected Software

1 affected component
Amazon Alexa+
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Amazon's red teaming efforts on the Alexa+ AI assistant, highlighting its potential benefits and security risks.

2

What security implications are discussed in the article?

The article raises concerns about the risks associated with AI assistants potentially malfunctioning or being exploited, leading to unintended actions.

3

What products or software are affected according to the article?

The primary product affected is the Amazon Alexa+ AI assistant.

4

What is the purpose of red teaming in the context of Amazon Alexa+?

Red teaming is utilized to identify vulnerabilities in the Alexa+ AI assistant before they can be exploited by malicious actors.

5

How might the Alexa+ AI assistant improve user experience?

If functioning correctly, Alexa+ could assist users with everyday tasks such as making dinner reservations and managing household repairs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203