THREAT OPS › Threat News › The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
<p class="wp-block-paragraph">Research by: <strong>Alexey Bukhteyev</strong></p>
<h1 class="wp-block-heading"><strong>Key Takeaways</strong></h1>
<ul class="wp-block-list"> <li>Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- https://openai.com/index/hugging-face-incident-and-the-road-ahead/url
- https://jfrog.com/artifactory/url
- https://docs.jfrog.com/artifactory/reference/setitempropertiesurl
- https://docs.jfrog.com/artifactory/reference/getstorageitemurl
- https://help.openai.com/en/articles/11487775-apps-in-chatgpt#important-actionsurl