New ChatGPT Flaws Allow Attackers to Exfiltrate Sensitive Data from Gmail, Outlook, and GitHub
ID: bb9f2d26-fb4b-52dc-9728-3edf0b52bb41
STIX ID: report--bb9f2d26-fb4b-52dc-9728-3edf0b52bb41
Feed Name: cybersecurityNews.com
Threat Score
Critical vulnerabilities dubbed ShadowLeak and ZombieAgent in ChatGPT’s Connectors and Memory allow attackers to perform zero‑click and one‑click server‑side data exfiltration from connected services (Gmail, Outlook, GitHub, Google Drive), achieve persistence by injecting memory rules, and propagate across organizations by harvesting and auto‑sending payloads; researchers reported the flaws and OpenAI deployed fixes in 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
