Actively Exploited ChatGPT Bug Puts Organizations at Risk
ID: 2e013ca6-7c0c-54b2-acf2-8480e337395f
STIX ID: report--2e013ca6-7c0c-54b2-acf2-8480e337395f
Feed Name: Dark Reading
Date Published: 2025-03-18
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Attackers are actively exploiting CVE-2024-27564, a server-side request forgery (SSRF) in ChatGPT's pictureproxy.php, with over 10,000 observed attempts from a single IP; the attacks—focused on U.S. financial institutions as well as government and healthcare targets—can force the application to make arbitrary requests and redirect users to malicious URLs. Veriti published IP indicators, recommends monitoring logs and hardening IPS/WAF/firewall configurations, and urges organizations to prioritize AI-related security gaps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
