“Claudy Day” Flaws Allow Data Theft via Fake Claude AI Ads, Report
ID: e81b8b3e-f130-522e-96e0-e696d8c38bec
STIX ID: report--e81b8b3e-f130-522e-96e0-e696d8c38bec
Feed Name: HackRead
Threat Score
Oasis Security disclosed a chained attack dubbed "Claudy Day" against Anthropic's Claude: hidden HTML in pre-filled chat URLs enables prompt injection, malicious Google Ads (via an open redirect) delivers targets through trusted-looking links, and the Anthropic Files API can be abused to quietly exfiltrate large amounts of stolen data; the prompt injection was patched after responsible disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
