{"id":213021,"date":"2026-05-13T03:55:05","date_gmt":"2026-05-13T07:55:05","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/05\/13\/new-zero-click-attack-lets-chatgpt-user-steal-data\/"},"modified":"2026-05-13T03:55:08","modified_gmt":"2026-05-13T07:55:08","slug":"new-zero-click-attack-lets-chatgpt-user-steal-data","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/05\/13\/new-zero-click-attack-lets-chatgpt-user-steal-data\/","title":{"rendered":"New Zero-Click Attack Lets ChatGPT User Steal Data"},"content":{"rendered":"<p><a href=\"https:\/\/www.infosecurity-magazine.com\/news\/new-zeroclick-attack-chatgpt\/\">New Zero-Click Attack Lets ChatGPT User Steal Data<\/a><\/p>\n<p><a href=\"https:\/\/www.infosecurity-magazine.com\/news\/new-zeroclick-attack-chatgpt\/\">https:\/\/www.infosecurity-magazine.com\/news\/new-zeroclick-attack-chatgpt\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-04-06 21:00:05<\/a><\/p>\n<p>Source Domain: <a href=\"www.infosecurity-magazine.com\">www.infosecurity-magazine.com<\/a><\/p>\n<p><strong>Summary of &#8220;ChatGPT\u2019s Agentic Shift, Boon for Users and Attackers&#8221; Article<\/strong><\/p>\n<p>The article discusses the newly discovered prompt injection technique, known as &#8216;ZombieAgent,\u2019 that was used to exploit vulnerabilities in the recently enhanced features of ChatGPT, a tool from Amazon\u2019s team of inventors. Zvika Babo, a security researcher from Radware, identified this method in September 2025 and alerted OpenAI through the BugCrowd platform. The discovered vulnerability exploited the capability for ChatGPT to connect to popular systems like Gmail, Outlook, Google Drive, and GitHub, allowing attackers to leak sensitive data from these services. While these new features enhance the chatbot\u2019s utility, they simultaneously create a new avenue for attackers to exfiltrate data through a technique that uses pre-built and static URLs. Babo&#8217;s research demonstrates how a zero-click attack can be executed and shows how persistence and propagation can be achieved, highlighting the need for more robust security measures.<\/p>\n<p><strong>Key Points:<\/strong><\/p>\n<ul>\n<li>Zvika Babo of Radware discovered a vulnerability known as \u2018ZombieAgent\u2019 allowing the leakage of sensitive data from services like Gmail via prompt injection techniques.<\/li>\n<li>This exploit targets the enhanced capabilities of ChatGPT to interact with popular systems, a boon acknowledged by Babo even though it presents new security risks.<\/li>\n<li>ZombieAgent bypasses URL modification defenses using pre-constructed static URLs corresponding to data characters.<\/li>\n<li>Successful attacks demonstrated include zero-click and one-click methods, and Babo also showed techniques for data persistence and propagation.<\/li>\n<li>Radware is set to hold a webinar on January 20, 2026, to further elaborate on the ZombieAgent exploitation method.<\/li>\n<\/ul>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Zero-Click Attack Lets ChatGPT User Steal Data https:\/\/www.infosecurity-magazine.com\/news\/new-zeroclick-attack-chatgpt\/ Publish Date: 2026-04-06 21:00:05 Source Domain:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":213022,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/assets.infosecurity-magazine.com\/webpage\/og\/745be30e-c623-41cf-a1be-286db63a538f.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[31,27],"class_list":["post-213021","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-exploit","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/213021"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=213021"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/213021\/revisions"}],"predecessor-version":[{"id":213023,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/213021\/revisions\/213023"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/213022"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=213021"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=213021"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=213021"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}