Tools

News

Notícias

Classificados

Cursos

Broker

IPv4:

IPv6:

 

UpOrDown
Ping
MTR
Smokeping
MTU Detect
Portscan
DNS
HTTP/SSL
My IP
IP Calc
IP Extractor

ShadowLeak hits ChatGPT research agent

Image © Arstechnica
A sophisticated prompt-injection technique, ShadowLeak, has been demonstrated against OpenAI's cloud-based research agent, exposing new risks in autonomous AI access to private data. The PoC shows data exfiltration can occur without user interaction.

A new attack named ShadowLeak targets OpenAI’s cloud-based ChatGPT research agent, revealing how data can be exfiltrated from Gmail inboxes via a prompt-injection chain.

Security researchers demonstrated a PoC in which a crafted prompt embedded in an email directed the agent to scan messages and extract names and addresses from a company’s HR emails, then send that data to an external endpoint.

OpenAI’s safeguards typically block actions like clicking links or using markdown links to prevent leakage, but the researchers showed the attack could bypass these measures by using the agent’s browser tool to open a public lookup page and log the retrieved information.

Radware’s analysis describes ShadowLeak as exploiting email access, tool use, and autonomous web calls to achieve silent data exfiltration, noting that OpenAI was alerted privately before mitigations were applied.

The incident highlights the ongoing risk of deploying autonomous AI agents with access to private communications. Industry groups urge careful deployment, layered security controls, and ongoing research to harden systems against prompt-injection exploits.

 

Arstechnica

Notícias relacionadas

Divergência MME e Aneel sobre cessão de postes
Brisanet dobra base móvel em 2025
Vivo anuncia Rogério Takayanagi como VP de engenharia e serviços
GT fará minuta da Política Nacional de Infraestruturas Críticas
Oi: Justiça prorroga blindagem de pagamentos até abril
Rogerio Takahyanagi assume Vivo como VP Engenharia

O ISP.Tools sobrevive graças aos anúncios.

Considere desativar seu bloqueador de anúncios.
Prometemos não ser intrusivos.

Consentimento para cookies

Utilizamos cookies para melhorar a sua experiência no nosso site.

Ao utilizar o nosso site, você concorda com o uso de cookies. Saiba mais