Theme:
Light Dark Auto
GeneralPoliticsBusinessEconomyTechnologyEnvironmentScienceSportsHealthEducationEntertainmentLifestyleGeneralNationWorld
TECHNOLOGY

A Single Poisoned Document Could Leak ‘Secret’ Data Via ChatGPT

Researchers at Black Hat revealed a vulnerability in OpenAI's ChatGPT Connectors allowing sensitive data extraction from linked accounts via indirect prompt injection. A single "poisoned" document can compromise a Google Drive account, enabling extraction of API keys and other secrets without user interaction. The attack, dubbed AgentFlayer, exploits a zero-click vulnerability, requiring only the target's email address. OpenAI has reportedly implemented mitigations, but the incident underscores the risks of connecting AI models to external systems and highlights the need for robust prompt injection protections.

Prepared by Jonathan Pierce and reviewed by editorial team.

Related News

Comments

JQJO App
Get JQJO App
Read news faster on our app
GET