home.social

#threatresearch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.

  1. Check Point posted this yesterday, if you missed it. Notice the word "covert."

    Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."

    Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT research.checkpoint.com/2026/t #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google

  2. Check Point posted this yesterday, if you missed it. Notice the word "covert."

    Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."

    Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT research.checkpoint.com/2026/t #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google

  3. Check Point posted this yesterday, if you missed it. Notice the word "covert."

    Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."

    Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT research.checkpoint.com/2026/t #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google

  4. Check Point posted this yesterday, if you missed it. Notice the word "covert."

    Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."

    Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT research.checkpoint.com/2026/t #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google

  5. Check Point posted this yesterday, if you missed it. Notice the word "covert."

    Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."

    Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT research.checkpoint.com/2026/t #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google

  6. New.

    Group-IB: Vwork: Weaponized Open-source Software as an Addon for Gigabud group-ib.com/blog/vwork-app-cl

    More:

    Infosecurity-Magazine: Gigabud Uses Android App Cloning to Evade Fraud Detection infosecurity-magazine.com/news #infosec #fraud #Android #threatresearch

  7. New.

    Group-IB: Vwork: Weaponized Open-source Software as an Addon for Gigabud group-ib.com/blog/vwork-app-cl

    More:

    Infosecurity-Magazine: Gigabud Uses Android App Cloning to Evade Fraud Detection infosecurity-magazine.com/news #infosec #fraud #Android #threatresearch

  8. New.

    Group-IB: Vwork: Weaponized Open-source Software as an Addon for Gigabud group-ib.com/blog/vwork-app-cl

    More:

    Infosecurity-Magazine: Gigabud Uses Android App Cloning to Evade Fraud Detection infosecurity-magazine.com/news #infosec #fraud #Android #threatresearch

  9. New.

    Group-IB: Vwork: Weaponized Open-source Software as an Addon for Gigabud group-ib.com/blog/vwork-app-cl

    More:

    Infosecurity-Magazine: Gigabud Uses Android App Cloning to Evade Fraud Detection infosecurity-magazine.com/news #infosec #fraud #Android #threatresearch

  10. New.

    Group-IB: Vwork: Weaponized Open-source Software as an Addon for Gigabud group-ib.com/blog/vwork-app-cl

    More:

    Infosecurity-Magazine: Gigabud Uses Android App Cloning to Evade Fraud Detection infosecurity-magazine.com/news #infosec #fraud #Android #threatresearch