Check Point demos ChatGPT cross-account leak: hidden task exfiltrates Gmail via JFrog metadata
TechNadu · x · 2026-09-09
- Check Point Research demonstrated a ChatGPT cross-account data leak: the victim sees a normal response while a hidden task accesses their connected Gmail data and relays it to an attacker.
- The covert channel abused metadata on a shared internal JFrog Artifactory instance, turning isolated ChatGPT containers into a cross-account communication channel.
Related event: Researchers demo cross-account ChatGPT data leak via hidden task(2 posts)→
More from Safety
- Anthropic safety expert puts odds of AI wiping out humanity above 10% as UK Parliament debates ASI ban — nordicinst · 2026-09-09
- New COLM Paper: AI Agent Swarms Can Split Attacks Across PRs, Making Oversight Far Harder — ronbodkin · 2026-09-09
- ">10% extinction risk?" AI safety figures clash over doom-mongering — mertdumenci · 2026-09-09
- If AI kills people, the backlash will be prison, not 'we should have listened' — Bedrovelsen · 2026-09-09
- AI cyber risk debate: Could a skilled hacker actually take down the power grid? — binarybits · 2026-09-09
- Claude Warns Users About Prompt Injection Risks in Tool-Recommendation Prompts — Beneficial-Theory339 · 2026-09-09