New attack on ChatGPT research agent pilfers secrets from Gmail inboxes
arstechnica.com·3w·

AI SYCOPHANCY IN FULL VIEW

Unlike most prompt injections, ShadowLeak executes on OpenAI’s cloud-based infrastructure.

Credit: Getty Images

The face-palm-worthy prompt injections against AI assistants continue. Today’s installment hits OpenAI’s Deep Research agent. Researchers recently devised an attack that plucked confidential information out of a user’s Gmail inbox and sent it to an attacker-controlled web server, with no interaction required on the part of the victim and no sign of exfiltration.

Deep Research is a ChatGPT-integrated AI agent that OpenAI introduced earlier this year. As its name is meant to convey, Deep Research performs complex, multi-step research on the Internet by tapping into a large array of resources,…

Similar Posts

Loading similar posts...