logo

“Claudy Day” Flaws Allow Data Theft via Fake Claude AI Ads, Report

ID: e81b8b3e-f130-522e-96e0-e696d8c38bec

STIX ID: report--e81b8b3e-f130-522e-96e0-e696d8c38bec

Feed Name: HackRead

Threat Score
65/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Oasis Security disclosed a chained attack dubbed "Claudy Day" against Anthropic's Claude: hidden HTML in pre-filled chat URLs enables prompt injection, malicious Google Ads (via an open redirect) delivers targets through trusted-looking links, and the Anthropic Files API can be abused to quietly exfiltrate large amounts of stolen data; the prompt injection was patched after responsible disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.