Technophile NewsTechnophile News
  • Home
  • News
  • PC
  • Phones
  • Android
  • Gadgets
  • Games
  • Guides
  • Accessories
  • Reviews
  • Spotlight
  • More
    • Artificial Intelligence
    • Web Stories
    • Press Release
What's On

How to Switch iPhones Without Losing a Thing

19 September 2025

Google dismantled Nest — can Gemini save what’s left?

19 September 2025

The Best Hoodies to Hibernate In All Year Long

19 September 2025

The Best Apple Watch Accessories

19 September 2025

Security researchers swiped secrets from Gmail. A ChatGPT agent helped

19 September 2025
Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact Us
Friday, September 19
Facebook X (Twitter) Instagram YouTube
Technophile NewsTechnophile News
Demo
  • Home
  • News
  • PC
  • Phones
  • Android
  • Gadgets
  • Games
  • Guides
  • Accessories
  • Reviews
  • Spotlight
  • More
    • Artificial Intelligence
    • Web Stories
    • Press Release
Technophile NewsTechnophile News
Home » Security researchers swiped secrets from Gmail. A ChatGPT agent helped
News

Security researchers swiped secrets from Gmail. A ChatGPT agent helped

By News Room19 September 20253 Mins Read
Facebook Twitter Pinterest LinkedIn Telegram Tumblr Reddit WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Email

Security researchers employed ChatGPT as a co-conspirator to plunder sensitive data from Gmail inboxes without alerting users. The vulnerability exploited has been closed by OpenAI but it’s a good example of the new risks inherent to agentic AI.

The heist, called Shadow Leak and published by security firm Radware this week, relied on a quirk in how AI agents work. AI Agents are assistants that can act on your behalf without constant oversight, meaning they can surf the web and click on links. AI companies laud them as a massive timesaver after users authorize their access to personal emails, calendars, work documents, etc.

Radware researchers exploited this helpfulness with a form of attack called a prompt injection, instructions that effectively get the agent to work for the attacker. The powerful tools are impossible to prevent without prior knowledge of a working exploit and hackers have already deployed them in creative ways including rigging peer review, executing scams, and controlling a smart home. Users are often entirely unaware something has gone wrong as instructions can be hidden in plain sight (to humans), for example as white text on a white background.

The double agent in this case was OpenAI’s Deep Research, an AI tool embedded within ChatGPT that launched earlier this year. Radware researchers planted a prompt injection in an email sent to a Gmail inbox the agent had access to. There it waited.

When the user next tries to use Deep Research, they would unwittingly spring the trap. The agent would encounter the hidden instructions, which tasked it with searching for HR emails and personal details and smuggling these out to the hackers. The victim is still none the wiser.

Getting an agent to go rogue — as well as managing to successfully get data out undetected, which companies can take steps to prevent — is no easy task and there was a lot of trial and error. “This process was a rollercoaster of failed attempts, frustrating roadblocks, and, finally, a breakthrough,” the researchers said.

Unlike most prompt injections, the researchers said Shadow Leak executed on OpenAI’s cloud infrastructure and leaked data directly from there. This makes it invisible to standard cyber defenses, they wrote.

Radware said the study was a proof-of-concept and warned that other apps connected to Deep Research — including Outlook, GitHub, Google Drive, and Dropbox — may be vulnerable to similar attacks. “The same technique can be applied to these additional connectors to exfiltrate highly sensitive business data such as contracts, meeting notes or customer records,” they said.

OpenAI has now plugged the vulnerability flagged by Radware in June, the researchers said.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

How to Switch iPhones Without Losing a Thing

19 September 2025

Google dismantled Nest — can Gemini save what’s left?

19 September 2025

The Best Hoodies to Hibernate In All Year Long

19 September 2025

The Best Apple Watch Accessories

19 September 2025

Meta Accused of Torrenting Porn to Advance Its Goal of AI ‘Superintelligence’

19 September 2025

AI Psychosis Is Rarely Psychosis at All

19 September 2025
Top Articles

Vivo X Fold 5 Colour Options, Specifications Teased Ahead of India Launch

2 July 202553 Views

Vivo X200 FE With 6,500mAh Battery, MediaTek Dimensity 9300+ SoC Launched: Specifications

23 June 202553 Views

Microsoft Introduces Mu AI Model Which Powers AI Agents in Windows 11 Settings

24 June 202550 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Don't Miss

Meta Accused of Torrenting Porn to Advance Its Goal of AI ‘Superintelligence’

19 September 2025

Strike 3 Holdings, a company that says it makes “high quality,” “feminist,” and “ethical” adult…

AI Psychosis Is Rarely Psychosis at All

19 September 2025

Anti-Trump Protesters Take Aim at ‘Naive’ US-UK AI Deal

19 September 2025

Cybercriminals Have a Weird New Way to Target You With Scam Texts

19 September 2025
Technophile News
Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Technophile News. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.