Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Flaw in AI APIs Allows Extraction of Hidden Data

Flaw in AI APIs Allows Extraction of Hidden Data

Posted on August 12, 2026 By CWS

A recent study has revealed a critical vulnerability in the APIs of major AI providers, including OpenAI, Anthropic, and Google, which enabled researchers to extract concealed reasoning and sensitive information from session logs. This flaw compromised encrypted reasoning objects, allowing weaker models to decode information from stronger counterparts.

Discovery of the API Flaw

The vulnerability was identified in the reasoning APIs used by these AI giants. Researchers discovered that encrypted reasoning blocks created during one session could be reused or replayed across different sessions. Remarkably, these blocks could be decoded by weaker models within the same provider’s ecosystem, revealing the hidden content.

The research paper titled “Stealing Reasoning Traces from Proprietary LLM APIs” outlined four potential exploitation paths: model distillation, extraction of private data, recovery of harmful content, and embedding prompt injections within opaque reasoning blocks.

Implications of the Vulnerability

During the study, the researchers managed to decode over 315,000 reasoning blocks from 6,708 public agent trajectories. This included identifying 704 distinct privacy artifacts from genuine user sessions, comprising API keys, passwords, and access tokens. While the cross-user attack didn’t allow unrestricted access to private chats, it did require an encrypted reasoning block and API access to a compatible model.

The findings were disclosed to the affected companies, including Microsoft and Hugging Face, resulting in mitigations that rendered the attacks non-reproducible by August 2026. However, the study did not find evidence of malicious exploitation in the wild.

Recommendations and Future Outlook

Developers are advised to remove reasoning blocks and opaque fields from shared traces and avoid sharing raw API transcripts, even if sanitized. The issue arises from a design intended to maintain reasoning across API calls, without exposing underlying plaintext.

Although the encryption was not compromised, the flaw allowed intact opaque blocks to be processed by providers, enabling cross-session and cross-model portability. The researchers emphasize that the vulnerability primarily affects developers who published raw logs with intact reasoning blocks.

Further research is needed to assess whether already-published blocks remain decodable. The study also highlights the lack of public acknowledgment from the affected providers, with the researchers relying on their reproducibility statement for confirmation that the attacks are no longer viable.

This latest discovery builds on previous research by cryptographer Matthew Green, emphasizing the need for ongoing scrutiny and improvement of AI security measures to prevent future vulnerabilities.

The Hacker News Tags:AI models, AI security, Anthropic, API flaw, Cybersecurity, data breach, data extraction, Encryption, Google, OpenAI, Privacy, reasoning blocks, research study, Vulnerability

Post navigation

Previous Post: 2.86 Billion Stolen Credentials Impact Cybersecurity Landscape
Next Post: Mindgard Secures $30M to Enhance AI Security

Related Posts

Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate The Hacker News
Weekly Security Highlights: AI Breaches, Bitcoin Heist, and More Weekly Security Highlights: AI Breaches, Bitcoin Heist, and More The Hacker News
China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems The Hacker News
Active Exploitation Detected in Gladinet and TrioFox Vulnerability Active Exploitation Detected in Gladinet and TrioFox Vulnerability The Hacker News
Orchid Security Enhances Enterprise Identity Observability Orchid Security Enhances Enterprise Identity Observability The Hacker News
Why 2026 Will be the Year of Machine-Speed Security Why 2026 Will be the Year of Machine-Speed Security The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chrome 151 Update Fixes Five Critical Security Flaws
  • SharePoint Exploit Emerges Following PoC Release
  • 737 VPN Extensions Expose Users to Proxy Risks
  • Fake CCleaner Download Spreads GhostDesk Spyware
  • Mindgard Secures $30M to Enhance AI Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chrome 151 Update Fixes Five Critical Security Flaws
  • SharePoint Exploit Emerges Following PoC Release
  • 737 VPN Extensions Expose Users to Proxy Risks
  • Fake CCleaner Download Spreads GhostDesk Spyware
  • Mindgard Secures $30M to Enhance AI Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark