Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    The Fire TV Stick 4K Max is back down to , its best price in a year

    The Fire TV Stick 4K Max is back down to $35, its best price in a year

    November 13, 2025
    Google’s NotebookLM will now do ‘deep research’

    Google’s NotebookLM will now do ‘deep research’

    November 13, 2025
    What the rise of CoreWeave tells us about the AI bubble

    What the rise of CoreWeave tells us about the AI bubble

    November 13, 2025
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » Researchers turned ChatGPT rogue and it robbed secrets from Gmail
    News

    Researchers turned ChatGPT rogue and it robbed secrets from Gmail

    News RoomBy News RoomSeptember 19, 20253 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Researchers turned ChatGPT rogue and it robbed secrets from Gmail

    Security researchers employed ChatGPT as a co-conspirator to plunder sensitive data from Gmail inboxes without alerting users. The vulnerability exploited has been closed by OpenAI but it’s a good example of the new risks inherent to agentic AI.

    The heist, called Shadow Leak and published by security firm Radware this week, relied on a quirk in how AI agents work. AI Agents are assistants that can act on your behalf without constant oversight, meaning they can surf the web and click on links. AI companies laud them as a massive timesaver after users authorize their access to personal emails, calendars, work documents, etc.

    Radware researchers exploited this helpfulness with a form of attack called a prompt injection, instructions that effectively get the agent to work for the attacker. The powerful tools are impossible to prevent without prior knowledge of a working exploit and hackers have already deployed them in creative ways including rigging peer review, executing scams, and controlling a smart home. Users are often entirely unaware something has gone wrong as instructions can be hidden in plain sight (to humans), for example as white text on a white background.

    The double agent in this case was OpenAI’s Deep Research, an AI tool embedded within ChatGPT that launched earlier this year. Radware researchers planted a prompt injection in an email sent to a Gmail inbox the agent had access to. There it waited.

    When the user next tries to use Deep Research, they would unwittingly spring the trap. The agent would encounter the hidden instructions, which tasked it with searching for HR emails and personal details and smuggling these out to the hackers. The victim is still none the wiser.

    Getting an agent to go rogue — as well as managing to successfully get data out undetected, which companies can take steps to prevent — is no easy task and there was a lot of trial and error. “This process was a rollercoaster of failed attempts, frustrating roadblocks, and, finally, a breakthrough,” the researchers said.

    Unlike most prompt injections, the researchers said Shadow Leak executed on OpenAI’s cloud infrastructure and leaked data directly from there. This makes it invisible to standard cyber defenses, they wrote.

    Radware said the study was a proof-of-concept and warned that other apps connected to Deep Research — including Outlook, GitHub, Google Drive, and Dropbox — may be vulnerable to similar attacks. “The same technique can be applied to these additional connectors to exfiltrate highly sensitive business data such as contracts, meeting notes or customer records,” they said.

    OpenAI has now plugged the vulnerability flagged by Radware in June, the researchers said.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleChina Turns Legacy Chips Into a Trade Weapon
    Next Article Fired CDC Director Says RFK Jr. Pressured Her to Blindly Approve Vaccine Changes

    Related Posts

    The Fire TV Stick 4K Max is back down to , its best price in a year

    The Fire TV Stick 4K Max is back down to $35, its best price in a year

    November 13, 2025
    Google’s NotebookLM will now do ‘deep research’

    Google’s NotebookLM will now do ‘deep research’

    November 13, 2025
    What the rise of CoreWeave tells us about the AI bubble

    What the rise of CoreWeave tells us about the AI bubble

    November 13, 2025
    The OnePlus 15 will go on sale in the US… sometime

    The OnePlus 15 will go on sale in the US… sometime

    November 13, 2025
    Apple’s Godzilla show Monarch is back in February

    Apple’s Godzilla show Monarch is back in February

    November 13, 2025
    Valve just built the Xbox that Microsoft is dreaming of

    Valve just built the Xbox that Microsoft is dreaming of

    November 13, 2025
    Our Picks
    Google’s NotebookLM will now do ‘deep research’

    Google’s NotebookLM will now do ‘deep research’

    November 13, 2025
    What the rise of CoreWeave tells us about the AI bubble

    What the rise of CoreWeave tells us about the AI bubble

    November 13, 2025
    How to Follow the Trajectory of Comet 3I/Atlas

    How to Follow the Trajectory of Comet 3I/Atlas

    November 13, 2025
    The OnePlus 15 is the phone to buy if you hate charging your phone

    The OnePlus 15 is the phone to buy if you hate charging your phone

    November 13, 2025
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    The OnePlus 15 will go on sale in the US… sometime News

    The OnePlus 15 will go on sale in the US… sometime

    By News RoomNovember 13, 2025

    OnePlus wants to sell you its new flagship phone; it just doesn’t know when it…

    Apple’s Godzilla show Monarch is back in February

    Apple’s Godzilla show Monarch is back in February

    November 13, 2025
    Valve just built the Xbox that Microsoft is dreaming of

    Valve just built the Xbox that Microsoft is dreaming of

    November 13, 2025
    Meet the Chinese Startup Using AI—and a Team of Human Workers—to Train Robots

    Meet the Chinese Startup Using AI—and a Team of Human Workers—to Train Robots

    November 13, 2025
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.