home.social

#threatresearch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.

  1. New.

    "Main payloads including AgentTesla, AsyncRat, RedLine, and Cobalt Strike run injected in memory, never touching disk."

    Picus: DarkTortilla Malware: How It Works and How to Test Your Defenses picussecurity.com/resource/blo #infosec #threatresearch #malware #phishing

  2. New.

    "Main payloads including AgentTesla, AsyncRat, RedLine, and Cobalt Strike run injected in memory, never touching disk."

    Picus: DarkTortilla Malware: How It Works and How to Test Your Defenses picussecurity.com/resource/blo #infosec #threatresearch #malware #phishing

  3. New.

    "Main payloads including AgentTesla, AsyncRat, RedLine, and Cobalt Strike run injected in memory, never touching disk."

    Picus: DarkTortilla Malware: How It Works and How to Test Your Defenses picussecurity.com/resource/blo #infosec #threatresearch #malware #phishing

  4. New.

    "Main payloads including AgentTesla, AsyncRat, RedLine, and Cobalt Strike run injected in memory, never touching disk."

    Picus: DarkTortilla Malware: How It Works and How to Test Your Defenses picussecurity.com/resource/blo #infosec #threatresearch #malware #phishing

  5. New.

    "Main payloads including AgentTesla, AsyncRat, RedLine, and Cobalt Strike run injected in memory, never touching disk."

    Picus: DarkTortilla Malware: How It Works and How to Test Your Defenses picussecurity.com/resource/blo #infosec #threatresearch #malware #phishing

  6. Check Point posted this yesterday, if you missed it. Notice the word "covert."

    Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."

    Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT research.checkpoint.com/2026/t #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google

  7. Check Point posted this yesterday, if you missed it. Notice the word "covert."

    Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."

    Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT research.checkpoint.com/2026/t #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google

  8. Check Point posted this yesterday, if you missed it. Notice the word "covert."

    Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."

    Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT research.checkpoint.com/2026/t #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google

  9. Check Point posted this yesterday, if you missed it. Notice the word "covert."

    Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."

    Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT research.checkpoint.com/2026/t #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google

  10. Check Point posted this yesterday, if you missed it. Notice the word "covert."

    Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."

    Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT research.checkpoint.com/2026/t #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google