#ShadowLeak
Was kann schon passieren, wenn man ChatGPT an eure e-mails lässt?

Richtig: nichts Gutes. Don't do it.

www.radware.com/blog/threat-...
ShadowLeak: A Zero-Click, Service-Side Attack Exfiltrating Sensitive Data Using ChatGPT’s Agent
www.radware.com
September 19, 2025 at 10:35 AM
New attack on ChatGPT research agent pilfers secrets from Gmail inboxes arstechnica.com/information-...
New attack on ChatGPT research agent pilfers secrets from Gmail inboxes
Unlike most prompt injections, ShadowLeak executes on OpenAI’s cloud-based infrastructure.
arstechnica.com
September 19, 2025 at 7:12 PM
A service-side flaw in OpenAI's ChatGPT, known as the #ShadowLeak attack, used indirect prompt injection to leak Gmail data.

Read: hackread.com/shadowleak-e...

#CyberSecurity #ChatGPT #OpenAI #Gmail #InfoSec #AI #Vulnerability
ShadowLeak Exploit Exposed Gmail Data Through ChatGPT Agent
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
September 22, 2025 at 10:18 AM
OpenAI plugs ShadowLeak bug in ChatGPT that let miscreants raid inboxes
OpenAI plugs ShadowLeak bug in ChatGPT that let miscreants raid inboxes
Radware says flaw enabled hidden email prompts to trick Deep Research agent into exfiltrating sensitive data ChatGPT's research assistant sprung a leak – since patched – that let attackers steal Gmail secrets with just a single carefully crafted email.…
dlvr.it
September 19, 2025 at 10:34 AM
A security flaw has been discovered in ChatGPT that could silently steal your Gmail data without you ever knowing. Security firm Radware has uncovered what they’re calling “ShadowLeak”.

#SecurityLand #CyberWatch #ChatGPT #Vulnerability #ShadowLeak

Read More: www.security.land/zero-click-c...
Zero-Click ChatGPT Vulnerability Exposes Gmail Data Without User Knowledge | Security Land
Critical ShadowLeak vulnerability in ChatGPT's Deep Research agent allows hackers to steal Gmail data without user interaction.
www.security.land
September 19, 2025 at 11:14 PM
Das "KI-Update" liefert drei mal pro Woche eine Zusammenfassung der wichtigsten KI-Entwicklungen. #KI update
KI-Update kompakt: ShadowLeak, Nvidia & OpenAI, Siemens, DeepSeek
Das "KI-Update" liefert drei mal pro Woche eine Zusammenfassung der wichtigsten KI-Entwicklungen.
www.heise.de
September 24, 2025 at 1:04 PM
New attack on #ChatGPT research agent pilfers secrets from Gmail inboxes

Unlike most prompt injections, ShadowLeak executes on OpenAI's cloud-based infrastructure.

arstechnica.com/information-...

#CyberSecurity #LLMs #AI
New attack on ChatGPT research agent pilfers secrets from Gmail inboxes
Unlike most prompt injections, ShadowLeak executes on OpenAI’s cloud-based infrastructure.
arstechnica.com
September 19, 2025 at 7:30 PM
'ShadowLeak' ChatGPT Attack Allows Hackers to Invisibly Steal Emails
'ShadowLeak' ChatGPT Attack Allows Hackers to Invisibly Steal Emails
The loophole allows cyberattackers to exfiltrate company data via OpenAI's infrastructure, leaving no trace at all on enterprise systems.
www.darkreading.com
September 19, 2025 at 7:48 PM
"People considering connecting LLM agents to their inboxes, documents, and other private resources should think long and hard about doing so, since these sorts of vulnerabilities aren’t likely to be contained anytime soon."

arstechnica.com/information-...
New attack on ChatGPT research agent pilfers secrets from Gmail inboxes
Unlike most prompt injections, ShadowLeak executes on OpenAI’s cloud-based infrastructure.
arstechnica.com
September 19, 2025 at 7:59 PM
'ShadowLeak' ChatGPT Attack Allows Hackers to Invisibly Steal Emails #cybersecurity #hacking #news #infosec #security #technology #privacy
ChatGPT 'ShadowLeak' Allows Hackers to Steal Emails
The loophole allows cyberattackers to exfiltrate company data via OpenAI's infrastructure, leaving no trace at all on enterprise systems.
www.darkreading.com
September 20, 2025 at 4:41 PM
ShadowLeak Zero-Click Flaw Leaks Gmail Data via OpenAI ChatGPT Deep Research Agent #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
September 20, 2025 at 5:51 AM
This Week in Security: The Shai-Hulud Worm, ShadowLeak, and Inside the Great Firewall
This Week in Security: The Shai-Hulud Worm, ShadowLeak, and Inside the Great Firewall
Hardly a week goes by that there isn’t a story to cover about malware getting published to a repository. Last week it was millions of downloads on NPM, but this …read more
hackaday.com
September 19, 2025 at 2:30 PM
ShadowLeak: Radware Uncovers Zero-Click Attack on ChatGPT
ShadowLeak: Radware uncovers zero-click attack on ChatGPT
Radware discovered a server-side data theft attack, dubbed ShadowLeak, targeting ChatGPT. OpenAI patched the zero-click vulnerability.
securityaffairs.com
September 19, 2025 at 12:02 AM
ShadowLeak Zero-Click Flaw Leaks Gmail Data via OpenAI ChatGPT Deep Research Agent
ShadowLeak Zero-Click Flaw Leaks Gmail Data via OpenAI ChatGPT Deep Research Agent
thehackernews.com
September 20, 2025 at 6:53 AM
New attack on ChatGPT research agent pilfers secrets from Gmail inboxes
arstechnica.com/information-...
New attack on ChatGPT research agent pilfers secrets from Gmail inboxes
Unlike most prompt injections, ShadowLeak executes on OpenAI’s cloud-based infrastructure.
arstechnica.com
September 19, 2025 at 11:48 AM
This Week in Security: The Shai-Hulud Worm, ShadowLeak, and Inside the Great Firewall
This Week in Security: The Shai-Hulud Worm, ShadowLeak, and Inside the Great Firewall
Hackaday Article
hackaday.com
September 19, 2025 at 2:06 PM
OpenAI plugs ShadowLeak bug in ChatGPT that enabled hidden email prompts to trick Deep Research agent into exfiltrating sensitive data
OpenAI plugs ShadowLeak bug in ChatGPT
: Radware says flaw enabled hidden email prompts to trick Deep Research agent into exfiltrating sensitive data
www.theregister.com
September 19, 2025 at 2:31 PM
ChatGPT Targeted in Server-Side Data Theft Attack

OpenAI has fixed this zero-click attack method called ShadowLeak by researchers.

#chatgpt #gpt #openai
ChatGPT Targeted in Server-Side Data Theft Attack
OpenAI has fixed this zero-click attack method called ShadowLeak by researchers.
www.securityweek.com
September 19, 2025 at 10:39 AM