ChatGPT's Memory Feature Supercharges Prompt Injection
ID: 5ab26c6b-a961-5d2d-bb77-039def24899d
STIX ID: report--5ab26c6b-a961-5d2d-bb77-039def24899d
Feed Name: Dark Reading
Radware researchers demonstrated "ZombieAgent," a proof-of-concept that amplifies indirect prompt injection (IPI) attacks against ChatGPT by abusing connectors (e.g., email integrations) and the model's long-term memory to persist malicious instructions and exfiltrate data via encoded URL schemes; OpenAI later implemented mitigations restricting attacker-supplied domains and modified-URL usage, but Radware warns structural defenses (like source-trust and intent-awareness) are still needed to fully address such risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
