logo

New ChatGPT Flaws Allow Attackers to Exfiltrate Sensitive Data from Gmail, Outlook, and GitHub

ID: bb9f2d26-fb4b-52dc-9728-3edf0b52bb41

STIX ID: report--bb9f2d26-fb4b-52dc-9728-3edf0b52bb41

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-01-08

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Critical vulnerabilities dubbed ShadowLeak and ZombieAgent in ChatGPT’s Connectors and Memory allow attackers to perform zero‑click and one‑click server‑side data exfiltration from connected services (Gmail, Outlook, GitHub, Google Drive), achieve persistence by injecting memory rules, and propagate across organizations by harvesting and auto‑sending payloads; researchers reported the flaws and OpenAI deployed fixes in 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.