Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Ancient giant octopuses were apex predators, study finds
    • Barcelona’s Zazume raises €2.5 million to scale its AI-powered rental management platform
    • How to Shop Like a Pro During Amazon Prime Day (2026)
    • CFTC seeks injunction in Kalshi Rhode Island dispute
    • As AI Expands, Erin Brockovich Taps Communities to Map Data Center Concerns
    • Direct-to-Cell Technology: Enabling Satellite Connectivity for Legacy Devices
    • How small businesses can leverage AI
    • Robots-Blog | Humanoide Robotik aus Deutschland: igus bringt neuen Serviceroboter auf den Markt
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Tuesday, June 2
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»ChatGPT falls to new data-pilfering attack as a vicious cycle in AI continues
    News

    ChatGPT falls to new data-pilfering attack as a vicious cycle in AI continues

    Editor Times FeaturedBy Editor Times FeaturedJanuary 8, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link


    To dam the assault, OpenAI restricted ChatGPT to solely open URLs precisely as offered and refuse so as to add parameters to them, even when explicitly instructed to do in any other case. With that, ShadowLeak was blocked, for the reason that LLM was unable to assemble new URLs by concatenating phrases or names, appending question parameters, or inserting user-derived knowledge right into a base URL.

    Radware’s ZombieAgent tweak was easy. The researchers revised the immediate injection to provide a whole listing of pre-constructed URLs. Every one contained the bottom URL appended by a single quantity or letter of the alphabet, for instance, instance.com/a, instance.com/b, and each subsequent letter of the alphabet, together with instance.com/0 by way of instance.com/9. The immediate additionally instructed the agent to substitute a particular token for areas.

    Diagram illustrating the URL-based character exfiltration for bypassing the permit listing launched in ChatGPT in response to ShadowLeak.

    Credit score:
    Radware

    Diagram illustrating the URL-based character exfiltration for bypassing the permit listing launched in ChatGPT in response to ShadowLeak.


    Credit score:

    Radware

    ZombieAgent labored as a result of OpenAI builders didn’t limit the appending of a single letter to a URL. That allowed the assault to exfiltrate knowledge letter by letter.

    OpenAI has mitigated the ZombieAgent assault by proscribing ChatGPT from opening any hyperlink originating from an electronic mail except it both seems in a well known public index or was offered instantly by the person in a chat immediate. The tweak is aimed toward barring the agent from opening base URLs that result in an attacker-controlled area.

    In equity, OpenAI is hardly alone on this never-ending cycle of mitigating an assault solely to see it revived by way of a easy change. If the previous 5 years are any information, this sample is prone to endure indefinitely, in a lot the way in which SQL injection and reminiscence corruption vulnerabilities proceed to supply hackers with the gasoline they should compromise software program and web sites.

    “Guardrails shouldn’t be thought of elementary options for the immediate injection issues,” Pascal Geenens, VP of menace intelligence at Radware, wrote in an electronic mail. “As a substitute, they’re a fast repair to cease a selected assault. So long as there isn’t a elementary resolution, immediate injection will stay an lively menace and an actual danger for organizations deploying AI assistants and brokers.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    CFTC seeks injunction in Kalshi Rhode Island dispute

    June 2, 2026

    Florida crackdown targets illegal machines in Sarasota

    June 2, 2026

    Hawthorne bankruptcy dispute targets Illinois racing funds

    June 2, 2026

    Kalshi debuts regulated crypto perpetual futures

    June 2, 2026

    Manchester gambling raid sparks wider enforcement focus

    June 2, 2026

    Burbank laboratory owner sentenced over Medicare gambling fraud

    June 1, 2026

    Comments are closed.

    Editors Picks

    Ancient giant octopuses were apex predators, study finds

    June 2, 2026

    Barcelona’s Zazume raises €2.5 million to scale its AI-powered rental management platform

    June 2, 2026

    How to Shop Like a Pro During Amazon Prime Day (2026)

    June 2, 2026

    CFTC seeks injunction in Kalshi Rhode Island dispute

    June 2, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Could it help prevent blindness in diabetics?

    December 18, 2024

    Intel shares spike after Softbank signs $2bn deal with chipmaker

    August 19, 2025

    Trump signs order blocking states from enforcing own AI rules

    December 12, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.