#shadowleak

[ follow ]
Information security
fromTheregister
2 days ago

OpenAI patches deja vu prompt injection vuln in ChatGPT

Multiple vulnerabilities in ChatGPT's Deep Research component enabled data exfiltration via prompt-injection techniques ShadowLeak and ZombieAgent despite applied patches.
Information security
fromThe Hacker News
3 months ago

ShadowLeak Zero-Click Flaw Leaks Gmail Data via OpenAI ChatGPT Deep Research Agent

A zero-click HTML prompt-injection (ShadowLeak) in ChatGPT Deep Research allowed exfiltration of Gmail inbox data via a single crafted email without user interaction.
fromTheregister
3 months ago

OpenAI plugs ShadowLeak bug in ChatGPT

ChatGPT's research assistant sprung a leak - since patched - that let attackers steal Gmail secrets with just a single carefully crafted email. Deep Research, a tool unveiled by OpenAI in February, enables users to ask ChatGPT to browse the internet or their personal email inbox and generate a detailed report on its findings. The tool can be integrated with apps like Gmail and GitHub, allowing people to do deep dives into their own documents and messages without ever leaving the chat window.
Information security
fromArs Technica
3 months ago

New attack on ChatGPT research agent pilfers secrets from Gmail inboxes

Accordingly, OpenAI mitigated the prompt-injection technique ShadowLeak fell to-but only after Radware privately alerted the LLM maker to it. A proof-of-concept attack that Radware published embedded a prompt injection into an email sent to a Gmail account that Deep Research had been given access to. The injection included instructions to scan received emails related to a company's human resources department for the names and addresses of employees. Deep Research dutifully followed those instructions.
Information security
Information security
fromSecurityWeek
3 months ago

ChatGPT Deep Research Targeted in Server-Side Data Theft Attack

ShadowLeak is a server-side data exfiltration method targeting ChatGPT's Deep Research, enabling silent extraction of inbox data via attacker-controlled URLs without user interaction.
[ Load more ]