A Single Poisoned Document Could Leak ‘Secret’ Data Via ChatGPT
Straight from #BlackHat2025 and picked up by WIRED:
Zenity Labs just issued a wake-up call to the entire AI industry. Michael Bargury (CTO & Co-founder) and Tamir Ishay Sharbat (Threat Researcher) unveiled #AgentFlayer: a set of 0click exploits that silently hijack enterprise AI agents with zero user interaction.
One of the vulnerabilities they uncovered in OpenAI’s Connectors enabled the extraction of sensitive data from a Google Drive account via an indirect prompt injection attack.
/f/121246/1920x1280/31dfc6c660/openai-google-drive-sec-2225304360.webp)