Tag: openai
-
282 iOS Apps Found Leaking LLM API Credentials in Network Traffic
Researchers have uncovered a systemic LLM credential exposure problem in the iOS ecosystem, with 282 AI”‘powered apps leaking exploitable API credentials and backend access mechanisms directly in network traffic. The findings highlight widespread misuse of OpenAI, Gemini, and other LLM provider APIs in mobile apps and show that many issues remain unpatched even after responsible…
-
Angreifer ohne Fachwissen hackt 14 Firmen mit Claude und Codex
Ein Angreifer hat mithilfe von Claudes Code-Agenten und OpenAIs Codex 14 Unternehmen kompromittiert. Seine mangelnden Fachkenntnisse glich die KI aus. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/angreifer-ohne-fachwissen-ki
-
New OpenAI Method Forecasts AI Risks Before Deployment
New Evaluation Method Predicts Harmful AI Behavior Before Launch. OpenAI says a new testing method called Deployment Simulation can better predict how AI models behave after deployment by using real user conversations rather than synthetic benchmarks. But researchers found models often detect when they are being tested, raising questions about the reliability of traditional safety…
-
OpenAI deepens Japan footprint with Hitachi deal
Hitachi will use OpenAI’s Codex agent to unpick ageing mission-critical systems and gain early access to its frontier AI models in a slew of high-profile Japanese partnerships for the US AI lab First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366644858/OpenAI-deepens-Japan-footprint-with-Hitachi-deal
-
Leak confirms OpenAI is testing a ChatGPT for Science subscription
OpenAI appears to be testing a new subscription and experience for science use cases, but it’s unclear if it’ll be available to everyone regardless of their background. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/artificial-intelligence/leak-confirms-openai-is-testing-a-chatgpt-for-science-subscription/
-
15 Malicious JetBrains Plugins Caught Stealing DeepSeek, OpenAI API Keys
Hackers are using 15 malicious JetBrains plugins posing as AI coding assistants to steal DeepSeek, OpenAI, and other developer API keys. First seen on hackread.com Jump to article: hackread.com/malicious-jetbrains-plugins-steal-deepseek-openai-api-keys/
-
LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosedLiteLLM is a widely deployed open-source AI gateway that brokers calls to more than 100 model providers behind one OpenAI-compatible interface.A server takeover exposes every provider key it…
-
Check Point beteiligt sich am ‘Trusted Access for Cyber”-Programm und an der ‘Daybreak”-Initiative von OpenAI
Check Point wurde als Mitglied des ‘Trusted Access for Cyber” (TAC)-Programms von OpenAI zugelassen und in OpenAIs Cybersicherheitsinitiative ‘Daybreak” aufgenommen. Die Bedrohungslandschaft wird von KI geprägt. Angreifer nutzen sie, um schneller zu agieren, Angriffe zu entwickeln und Schwachstellen in großem Umfang aufzudecken. IT-Sicherheitsexperten benötigen für die Absicherung ihrer IT-Umgebungen mindestens gleichwertige oder sogar stärkere Fähigkeiten.…
-
Check Point erhält exklusiven GPT-5.5-Zugang von OpenAI
Mit der Aufnahme in ‘Trusted Access for Cyber” und der Beteiligung an ‘Daybreak” stärkt Check Point seine KI-Strategie für die Unternehmenssicherheit. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/check-point-erhaelt-exklusiven-gpt-5-5-zugang-von-openai/a45463/
-
KI-Governance im Fokus: Was der Lockdown Mode von OpenAI wirklich sagt
OpenAI hat aktuell den »Lockdown Mode« für ChatGPT angekündigt. Dabei tat das Unternehmen etwas Bemerkenswertes: Es bestätigte öffentlich, dass Prompt Injection über MCP-Konnektoren ein ernstes unternehmerisches Exfiltrationsrisiko darstellt. Es ist ernst genug, um darauf architektonisch zu reagieren. Für Sicherheits- und Compliance-Verantwortliche in deutschen Unternehmen, ob Mittelstand oder DAX-Konzern, ist diese Bestätigung wichtig und hat direkte……
-
Lockdown Mode von OpenAI: Was deutsche Unternehmen für KI-Governance und Compliance beachten sollten
Der neue Lockdown Mode für ChatGPT soll das Risiko reduzieren, dass sensible Informationen über externe Verbindungen, Tools oder Konnektoren abfließen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/lockdown-mode-von-openai-was-deutsche-unternehmen-fuer-ki-governance-und-compliance-beachten-sollten/a45445/
-
‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers
The company says there’s little evidence it influenced any real policy discussion. First seen on cyberscoop.com Jump to article: cyberscoop.com/openai-china-influence-campaign-chatgpt/
-
‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers
The company says there’s little evidence it influenced any real policy discussion. First seen on cyberscoop.com Jump to article: cyberscoop.com/openai-china-influence-campaign-chatgpt/
-
OpenAI Expands ChatGPT Lockdown Mode to Millions of Eligible Users
OpenAI is expanding ChatGPT Lockdown Mode to more users, limiting web-connected tools to reduce the risks of prompt injection and data leakage. The post OpenAI Expands ChatGPT Lockdown Mode to Millions of Eligible Users appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-openai-expands-chatgpt-lockdown-mode-millions-users/
-
OpenAI Unveils ChatGPT Account Security Controls
OpenAI brings Lockdown Mode and Active Sessions to ChatGPT to curb prompt injection data theft First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chatgpt-lockdown-mode-active/
-
OpenAI is locking down parts of ChatGPT to reduce data theft risks
OpenAI has started rolling out Lockdown Mode for ChatGPT, an optional security setting that restricts access to external resources and several product capabilities. It is … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/08/openai-lockdown-mode-available/
-
New ChatGPT Lockdown Mode Aims to Block Prompt Injection and Data Exfiltration Attacks
OpenAI this week introduced Lockdown Mode, a security-focused setting for ChatGPT designed to reduce the risk of data exfiltration from prompt-injection attacks. The feature is rolling out to eligible personal accounts (Free, Go, Plus, Pro) and self-serve ChatGPT Business workspaces, and managed-workspace administrators can assign a Lockdown Mode role to members. Prompt injection is a…
-
OpenAI unveils Lockdown Mode to protect sensitive data from prompt injection attacks
Even with Lockdown Mode, ChatGPT could be still vulnerable to prompt injections, but the goal is to reduce the likelihood that sensitive data gets shared in the process. First seen on techcrunch.com Jump to article: techcrunch.com/2026/06/06/openai-unveils-lockdown-mode-to-protect-sensitive-data-from-prompt-injection-attacks/
-
New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration
OpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts to reduce the risk of data exfiltration arising from prompt injection attacks.The feature is primarily designed for people and organizations that handle sensitive data and require stricter protection guarantees. Lockdown Mode is available to logged-in users across Free, Go, Plus,…
-
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.The vulnerability has been codenamed HTTP/2 Bomb by Calif.”The vulnerable behavior exists in each server’s default HTTP/2 configuration,” the company said, adding it was discovered by OpenAI Codex by chaining First seen on…
-
OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models
OpenAI says it’s rolling out a new update that improves the existing GPT-5.5 Instant model, and this move comes ahead of the scheduled retirement of multiple legacy models, including o3. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/artificial-intelligence/openai-upgrades-gpt-55-as-it-plans-to-retire-legacy-chatgpt-models/
-
For CISOs, dawn of OpenAI Daybreak brings good and bad news
OpenAI Daybreak shows how AI reshapes vulnerability discovery. But AI-driven security tools raise accountability questions and fuel the AI arms race between defenders and attackers. First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366643546/For-CISOs-dawn-of-OpenAI-Daybreak-brings-good-and-bad-news
-
OpenAI brings frontier AI to existing AWS environments
OpenAI frontier models and Codex are now available on AWS, giving customers access to OpenAI capabilities within AWS environments and the controls needed to move more quickly … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/02/openai-models-and-codex-on-aws/
-
Anthropic Submits Pre-IPO SEC Filing, Leads Market Cap Fight
Frontier AI Market Gains Helped Anthropic Move From Challenger to Category Leader Anthropic’s new $965 billion Series H valuation, growing use of Claude for AI coding and an increasing share of the enterprise AI market indicate OpenAI’s early lead in frontier models has disappeared as customers have shifted their spending, workloads and token usage to…
-
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
Tags: android, attack, authentication, breach, cybersecurity, github, malicious, openai, supply-chain, toolCybersecurity researchers have disclosed details of a new malicious supply chain campaign that’s targeting developers using OpenAI Codex through a legitimate-looking remote web UI.The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for download from the…
-
AI Powered Nmap using ShellGPT
Overview This article examines how pairing ShellGPT, an AI-powered command-line assistant driven by the OpenAI API, with Nmap fundamentally changes the pace and First seen on hackingarticles.in Jump to article: www.hackingarticles.in/ai-powered-nmap-using-shellgpt/
-
27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens
A malicious Codex UI npm package with 27,000 weekly downloads was caught exfiltrating OpenAI refresh tokens, exposing developers to account takeover risks. First seen on hackread.com Jump to article: hackread.com/codex-ui-tool-secretly-stole-openai-refresh-tokens/
-
ISMG Editors: The Governance Questions Haunting OpenAI
Also: Rethinking SASE and AI’s Impact on the Cyber Workforce. In this week’s panel, four ISMG editors discussed what the Musk vs. Altman trial exposed about OpenAI’s governance program, how AI is reshaping the way enterprises think about security and why Cisco, Cloudflare, Arctic Wolf and other firms are redesigning their workforces for the AI…
-
1Password and OpenAI collaborate on secure credential access for AI coding agents
First seen on scworld.com Jump to article: www.scworld.com/brief/1password-and-openai-collaborate-on-secure-credential-access-for-ai-coding-agents
-
KI-Angriffe 2026: Check Point warnt vor AI-Hacking, Jailbreaks und gestohlenen OpenAIKeys
Was bislang als experimentelle Bedrohung galt, entwickelt sich jetzt mit rasanter Geschwindigkeit zum skalierbaren Geschäftsmodell für Angreifer weltweit. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ki-angriffe-2026-check-point-warnt-vor-ai-hacking-jailbreaks-und-gestohlenen-openai-api-keys/a45280/

