TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Infosecurity Magazine

ChatGPT Security Issue Enabled Data Theft via Single Prompt

2026-03-31 · Read original ↗

ATT&CK techniques detected

2 predictions
T1041Exfiltration Over C2 Channel
73%
"also being used to discuss personal issues, like their health, personal finances or mental wellbeing. users expect this information to remain within the system, protected from exfiltration by appropriate guardrails. however, check point found that it was possible to bypass these …"
T1204.001Malicious Link
37%
"the malicious prompt to exploit the vulnerability. when asked if the information was sent to a third - party, chatgpt responded that it had not, seemingly unaware that because of its actions a server operated by the attacker received highly sensitive data extracted from the conve…"

Summary

OpenAI has patched vulnerability, which Check Point said was because of a DNS loophole