Connect with us

Technology

AI flaw leaked Gmail data before OpenAI patch

Published

on

AI flaw leaked Gmail data before OpenAI patch

NEWYou can now listen to Fox News articles!

A new cybersecurity warning reveals how hackers briefly weaponized ChatGPT’s Deep Research tool. The attack, called ShadowLeak, allowed them to steal Gmail data through a single invisible prompt — no clicks, no downloads and no user action required.

Researchers at Radware discovered the zero-click vulnerability in June 2025. OpenAI patched it in early August after being notified, but experts warn that similar flaws could reappear as artificial intelligence (AI) integrations expand across popular platforms like Gmail, Dropbox and SharePoint.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM/NEWSLETTER

HACKER EXPLOITS AI CHATBOT IN CYBERCRIME SPREE

Advertisement

Gmail data leaked in a zero-click attack requiring no user action.  (Kurt “CyberGuy” Knutsson)

How the ShadowLeak attack worked

Attackers embedded hidden instructions into an email using white-on-white text, tiny fonts or CSS layout tricks. The email looked completely harmless. But when a user later asked ChatGPT’s Deep Research agent to analyze a Gmail inbox, the AI unknowingly executed the attacker’s commands.

The agent then used its built-in browser tools to exfiltrate sensitive data to an external server, all within OpenAI’s own cloud environment, beyond the reach of antivirus or enterprise firewalls.

Unlike previous prompt-injection attacks that ran on the user’s device, ShadowLeak unfolded entirely in the cloud, making it invisible to local defenses.

GOOGLE CONFIRMS DATA STOLEN IN BREACH BY KNOWN HACKER GROUP

Advertisement

Hidden prompts expose how hackers silently hijacked ChatGPT’s AI agent. (Kurt “CyberGuy” Knutsson)

Why this threat matters

The Deep Research agent was designed to perform multistep research and summarize online data, but its wide access to third-party apps like Gmail, Google Drive and Dropbox also opened the door to abuse.

Radware researchers said the attack involved encoding personal data in Base64 and appending it to a malicious URL, disguised as a “security measure.” Once sent, the agent believed it was acting normally.

The real danger lies in the fact that any connector could be exploited the same way if attackers manage to hide prompts in analyzed content.

What security experts say

“The user never sees the prompt. The email looks normal, but the agent follows the hidden commands without question,” the researchers explained.

Advertisement

In a separate experiment, security firm SPLX showed another weakness: ChatGPT agents could be tricked into solving CAPTCHAs by inheriting a manipulated conversation history. Researcher Dorian Schultz noted that the model even mimicked human cursor movements, bypassing tests meant to block bots.

These incidents highlight how context poisoning and prompt manipulation can silently break AI safeguards.

GOOGLE AI EMAIL SUMMARIES CAN BE HACKED TO HIDE PHISHING ATTACKS

Experts warn future AI integrations could face the same hidden threat. (Kurt “CyberGuy” Knutsson)

How to protect yourself from ShadowLeak-style attacks

Even though OpenAI has patched the ShadowLeak flaw, it’s smart to stay proactive. Cybercriminals are always looking for new ways to exploit AI agents and integrations. So, taking these precautions now can help keep your accounts and personal data secure.

Advertisement

1) Turn off unused integrations

Every connection is a potential entry point. Disable any integrations you’re not actively using, such as Gmail, Google Drive or Dropbox. Fewer linked apps mean fewer ways for hidden prompts or malicious scripts to access your information.

2) Use a personal data removal service

Limit how much of your personal data is floating around the web. Data removal services can automatically remove your private details from people search sites and data broker databases, reducing what attackers can find and use against you. While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

3) Avoid analyzing unknown content

Treat every email, attachment or document with caution. Don’t ask AI tools to analyze content from unverified or suspicious sources. Hidden text, invisible code or layout tricks could trigger silent actions that expose your private data.

Advertisement

4) Watch for security updates

Stay alert for updates from OpenAI, Google, Microsoft and other platforms. Security patches close newly discovered vulnerabilities before hackers can exploit them. Turn on automatic updates so you’re always protected without having to think about it. 

5) Use strong antivirus software

A strong antivirus program adds another wall of defense. These tools detect phishing links, hidden scripts and AI-driven exploits before they cause harm. Schedule regular scans and keep your protection up to date.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.

6) Use layered protection

Think of your security like an onion; more layers make it tougher to breach. Keep your browser, operating system and endpoint security software fully updated. Add real-time threat detection and email filtering to block malicious content before it lands in your inbox.

Advertisement

Kurt’s key takeaways

AI is evolving faster than most security systems can keep up with. Even when companies move quickly to patch vulnerabilities, clever attackers find new ways to exploit integrations and context memory. Staying alert and limiting what your AI agents can access is your best defense.

Would you still trust an AI assistant with access to your personal email after learning how easily it can be tricked? Let us know by writing to us at Cyberguy.com..

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.

Copyright 2025 CyberGuy.com.  All rights reserved.

Advertisement

Technology

4chan’s creator says ‘Epstein had nothing to do’ with creating infamous far-right board /pol/

Published

on

4chan’s creator says ‘Epstein had nothing to do’ with creating infamous far-right board /pol/

Epstein had nothing to do with the reintroduction of a politics board to 4chan, nor anything else related to the site. The decision to add the board was made weeks beforehand, and the board was added almost 24 hours prior to a first, chance encounter at a social event. His assistant reached out to me afterward, and I met with him one time for an unmemorable lunch meeting. This happened at a time when I was meeting hundreds of people a month while speaking and networking at tech events.

I did not meet him again nor maintain contact. I regret having ever encountered him at all, and have deep sympathy for all of his victims.

Continue Reading

Technology

Woman owes $3,556 for cruise she already paid for after falling victim to elaborate Zelle scam

Published

on

Woman owes ,556 for cruise she already paid for after falling victim to elaborate Zelle scam

NEWYou can now listen to Fox News articles!

A family vacation turned into a five-year nightmare. And it started with one payment.

L. Williams found a cruise consultant online who booked her family a week on Carnival Freedom. Great price. One catch. He only accepted Zelle. She sent $3,556. The family sailed the Western Caribbean. Gorgeous sunsets. Wonderful memories.

Five years later, she tried to book another cruise. Nope.

Carnival told her she was on the Do Not Sail list. Turns out her “consultant” pocketed the Zelle cash, then used a stolen credit card to book the trip. When the real cardholder disputed the charge, Williams got the blame.

Advertisement

DON’T LOCK YOUR FAMILY OUT: A DIGITAL LEGACY GUIDE

She now owes $3,556 for a trip she already paid for. Banned for life. The scammer’s phone? Disconnected. (Of course.)

The deals are real right now

Here’s what you need to know. The cheapest window for domestic spring break flights is about 43 days before departure. For late March trips, that’s this week. Wait until late February, and prices jump 20% to 25%. That’s your cash walking out the door.

Fly Tuesday, Wednesday or Saturday, and save up to 30% over weekend flights. Set Google Flights alerts now. Caribbean fares are down 17% from last year. 

Bundle flights with hotels through Costco, Expedia or Delta Vacations, and you can knock hundreds off the total.

Advertisement

Travelers arrive at Los Angeles International Airport on Monday, Nov. 3, 2025 in Los Angeles, CA.  (Juliana Yamada / Los Angeles Times via Getty Images)

Scammers circling like sharks

Williams’ story isn’t a one-off. Over 38 million people are expected to cruise in 2026, and scammers know it. Here are the big cons I’m seeing.

  • The Google trap. Fake cruise line phone numbers are showing up in search results. One man called what he thought was Carnival’s customer service line and got hit with a $650 per person “docking fee.” That’s not a thing. Real cruise lines don’t charge surprise fees by phone. Always go directly to the official website for contact info.
  • The free cruise postcard. Got one in the mail? Toss it. The fine print buries you in hundreds of dollars of hidden fees and a windowless cabin with bunk beds. How romantic. One investigation found the company behind these changes its name every year so you can’t look them up.

AI JOBS THAT PAY $200K OR MORE

  • The Facebook agent. Scammers pose as travel agents in Facebook groups and collect payments through Zelle, Venmo or Cash App. Then they vanish. These apps have zero buyer protection. They’re for sending money to people you trust, not strangers selling Caribbean getaways.
  • Your three rules: Always pay with a credit card. Never call a customer service number from a Google search, go to the official site. If you want a travel agent, verify them at ASTA.org.

Book smart and you’ll be sipping something tropical in a few weeks. Book carelessly and you might end up on the Do Not Sail list, which, ironically, is the worst kind of cruise control.

TRAVELING SOON? KNOW HOW TO NAVIGATE FLIGHT CANCELLATIONS NOW

If anyone you know is booking a spring break trip, send them this first. It takes two seconds to forward and could save them thousands. One payment to the wrong person cost a woman her vacation money, her cruise line privileges and years of debt headaches.

Advertisement

An RV parked in a campsite during the early autumn.  (iStock)

Get tech-smarter on your schedule

Award-winning host Kim Komando is your secret weapon for navigating tech.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

National radio show airing on 500+ stations, a free daily newsletter, videos on YouTube, plus the podcast wherever you listen. 

Advertisement

Copyright 2026, WestStar Multimedia Entertainment. All rights reserved.

Continue Reading

Technology

Tenways’ compact e-bike twists and folds to go flat

Published

on

Tenways’ compact e-bike twists and folds to go flat

Tenways just launched its new CGO Compact electric bike in Europe that’s designed to fit into tight spaces like car trunks, apartment hallways, and train compartments.

To achieve this, the CGO Compact is fitted with small 20-inch wheels, folding pedals, and a handlebar fitted with a twistable stem to create a slim, wall-hugging profile. The adjustable steering column and low-step through frame also make it suitable for a wide range of rider heights, so it could be a good shareable e-bike for families. And its MIK HD rear carrier system is good for hauling up to 27kg (almost 60 pounds) around town, with mounting points for additional accessories like a crate or child seat.

Tenways might not be a household name globally, but the Chinese e-bike company headquartered in the Netherlands is making a name for itself in Europe thanks to aggressive pricing, sleek designs, and over 1,500 shops and service centers. And while the CGO Compact’s €1,999 (about $2,365) price tag isn’t cheap, it’s well below the €2,681 average for European e-bikes.

The company does sell e-bikes in the US, but the CGO Compact is only for sale in Europe as of today. It features a 250W rear-hub motor connected to a Gates Carbon belt drive for maintenance-free propulsion. It promises a range of up to 100km from its 500Wh removable battery, but its single-speed drivetrain produces only 45Nm of torque so it’s best suited for relatively flat cities. If your commute does stray from asphalt then the suspension seat post should help absorb bumps. There’s also an integrated torque sensor to ensure the smooth delivery of pedal-assisted power, and Tektro hydraulic disc brakes should keep any sudden stops under control.

The CGO Compact lives up to its name regarding size, but it’s not all that lightweight. Stripped down it weighs 19.8kg (almost 44 pounds), or 22.1kg (almost 49 pounds) with all the accessories you’ll want in wet urban environments. That makes it heavier than many full-sized e-bikes, even from Tenways, and less versatile than the excellent 20-inch Brompton G foldable which also weighs less but costs more than twice as much.

Advertisement
Continue Reading

Trending