logo

Actively Exploited ChatGPT Bug Puts Organizations at Risk

ID: 2e013ca6-7c0c-54b2-acf2-8480e337395f

STIX ID: report--2e013ca6-7c0c-54b2-acf2-8480e337395f

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-03-18

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Attackers are actively exploiting CVE-2024-27564, a server-side request forgery (SSRF) in ChatGPT's pictureproxy.php, with over 10,000 observed attempts from a single IP; the attacks—focused on U.S. financial institutions as well as government and healthcare targets—can force the application to make arbitrary requests and redirect users to malicious URLs. Veriti published IP indicators, recommends monitoring logs and hardening IPS/WAF/firewall configurations, and urges organizations to prioritize AI-related security gaps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.