Tools

News

Notícias

Classificados

Cursos

Broker

IPv4:

IPv6:

 

UpOrDown
Ping
MTR
Smokeping
MTU Detect
Portscan
DNS
HTTP/SSL
My IP
IP Calc
IP Extractor

ChatGPT Faces New Data-Pilfering Attack

Image © Arstechnica
A new, refined data-exfiltration threat demonstrates why guardrails against AI attacks are not a cure-all. Researchers warn that the cycle of vulnerability, mitigation, and bypass continues.

A familiar pattern persists in AI security: researchers identify a vulnerability, attackers abuse it, platforms install guardrails that block the tactic, and then a new tweak emerges that threatens users once again. Guardrails often target a single technique and are reactive, leaving the broader class of vulnerabilities only partially addressed.

Radware has highlighted a newer variant dubbed ZombieAgent, described as an evolved ShadowLeak that can siphon a user’s private data directly from ChatGPT servers. The attack can store entries in the user’s long-term memory, increasing persistence and making it harder to eradicate from the system.

The ZombieAgent approach builds on ShadowLeak, which OpenAI mitigated after Radware disclosed it last September. The security firm contends that a modest twist revived the technique, naming the revised attack ZombieAgent.

OpenAI’s mitigations previously constrained ChatGPT to open URLs exactly as provided and to avoid appending extra parameters. ZombieAgent, however, uses pre-constructed URLs with a single letter appended (for example, example.com/a, example.com/b, etc.), enabling data exfiltration even when the base URL is otherwise controlled.

Security researchers emphasize that the root cause remains the model’s difficulty distinguishing between valid prompts and content inserted by attackers. Pascal Geenens, Radware’s VP of threat intelligence, argues that guardrails are quick fixes for specific attacks and do not constitute fundamental solutions. As long as the underlying vulnerability persists, prompt injection will remain a risk for AI assistants and their users.

 

Arstechnica

Notícias relacionadas

Código do Contribuinte: vetos bloqueiam 70%
Bahia e Sergipe ganham novas áreas locais
Network slicing avança e 33 operadoras já ofertam
Bancos criam cofres de pureza de dados
Anatel abre reforma de regimento
TI B2B 2027: startups no stack

O ISP.Tools sobrevive graças aos anúncios.

Considere desativar seu bloqueador de anúncios.
Prometemos não ser intrusivos.

Consentimento para cookies

Utilizamos cookies para melhorar a sua experiência no nosso site.

Ao utilizar o nosso site, você concorda com o uso de cookies. Saiba mais