Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
OpenAI Resolves ChatGPT Data Breach and Codex Vulnerability

OpenAI Resolves ChatGPT Data Breach and Codex Vulnerability

Posted on March 30, 2026 By CWS

A recent vulnerability in OpenAI’s ChatGPT was identified, which allowed unauthorized access to sensitive user data without their knowledge. This security flaw was uncovered by Check Point, revealing how a single malicious prompt could potentially exploit the system and extract private conversations and files. OpenAI has since addressed this weakness, ensuring that no evidence of exploitation has been reported.

Exploiting the ChatGPT Vulnerability

ChatGPT was built with security measures to prevent unauthorized data sharing. However, researchers discovered that by using a side channel within the Linux runtime, these safeguards could be bypassed. This method utilized a hidden DNS-based communication path, potentially allowing attackers to execute commands remotely without user consent. The absence of warning signs or user notifications made this vulnerability a significant blind spot in AI system security.

Attackers could leverage this vulnerability by enticing users to input malicious prompts under false pretenses, such as unlocking premium features. This threat is even more concerning when embedded in custom GPTs, where users might not even realize they are executing harmful commands.

Implications for AI Security

With AI tools like ChatGPT being increasingly utilized in enterprise environments, the need for robust security measures becomes apparent. The uncovered vulnerability highlights the necessity for organizations to implement additional security layers to counteract potential prompt injections and other unforeseen behaviors in AI systems.

Eli Smadja from Check Point Research emphasized that as AI platforms evolve, relying solely on native security controls is insufficient. Organizations must establish independent security structures to operate safely in the AI era, rather than merely reacting to security incidents as they arise.

Codex Vulnerability and GitHub Token Compromise

In conjunction with the ChatGPT issue, a critical vulnerability was discovered in OpenAI’s Codex, which could have led to unauthorized access to GitHub credentials. This flaw was due to improper input sanitization during task execution, allowing attackers to inject commands through the GitHub branch name parameter.

This security breach was patched by OpenAI in February 2026, following its discovery in December 2025. The vulnerability affected several OpenAI platforms including the ChatGPT website and Codex extensions. BeyondTrust highlighted the risks of privileged access in AI coding agents, which can pave the way for large-scale attacks on enterprise systems.

The findings underscore the importance of treating AI environments with the same security rigor as any traditional application, as the integration of AI into developer workflows expands the potential attack surface.

As AI tools become more integral to operations, maintaining a secure environment is crucial to prevent unauthorized data access and ensure the safety of sensitive information.

The Hacker News Tags:AI development, AI security, AI vulnerability, ChatGPT, Codex, command injection, cyber threats, Cybersecurity, data breach, data security, GitHub, machine learning, OpenAI, Software, Technology

Post navigation

Previous Post: Top AWS Monitoring Tools for Optimal Cloud Performance
Next Post: Rundll32 and WebDAV: New ClickFix Variant Evades Detection

Related Posts

300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide 300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide The Hacker News
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days The Hacker News
China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats The Hacker News
n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens The Hacker News
5 Threats That Reshaped Web Security This Year [2025] 5 Threats That Reshaped Web Security This Year [2025] The Hacker News
Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerability in Open VSX Exposes Users to Risk
  • TA446 Hackers Unleash DarkSword Kit on iOS Devices
  • Rundll32 and WebDAV: New ClickFix Variant Evades Detection
  • OpenAI Resolves ChatGPT Data Breach and Codex Vulnerability
  • Top AWS Monitoring Tools for Optimal Cloud Performance

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerability in Open VSX Exposes Users to Risk
  • TA446 Hackers Unleash DarkSword Kit on iOS Devices
  • Rundll32 and WebDAV: New ClickFix Variant Evades Detection
  • OpenAI Resolves ChatGPT Data Breach and Codex Vulnerability
  • Top AWS Monitoring Tools for Optimal Cloud Performance

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark