Exploited ChatGPT Vulnerability Poses Risks to Organizations

Share post:

A server-side request forgery (SSRF) vulnerability in OpenAI’s ChatGPT infrastructure, tracked as CVE-2024-27564, is being actively exploited by attackers to redirect users to malicious URLs, placing organizations at significant risk.

Researchers from cybersecurity firm Veriti have identified that this medium-severity flaw allows cybercriminals to inject crafted URLs into ChatGPT’s system, compelling the application to make arbitrary requests. This exploitation can lead to unauthorized access and data breaches. Notably, over 10,000 exploit attempts were recorded within a single week from a lone malicious IP address, underscoring the vulnerability’s appeal to threat actors.

The attacks have predominantly targeted financial institutions and U.S. government organizations, highlighting the critical need for robust cybersecurity measures in these sectors. Alarmingly, Veriti’s analysis revealed that 35% of examined organizations were susceptible due to misconfigurations in intrusion prevention systems, web application firewalls, and firewall settings.

SSRF vulnerabilities enable attackers to manipulate server-side applications into making unauthorized requests to internal or external systems, potentially leading to data exposure or further system compromises. In this instance, the flaw permits adversaries to direct ChatGPT to access unintended URLs, facilitating a range of malicious activities.

 

SUBSCRIBE NOW

Related articles

ChatGPT’s New Shopping Assistant Could Disrupt Google and Amazon Search

OpenAI has added real-time shopping features to ChatGPT, allowing users to search for and compare products in plain...

Duolingo’s AI-First Strategy Replaces Hundreds of Contractors in Major Shift

Duolingo, the language learning company, is moving to an AI-first operational model, replacing hundreds of contract workers with...

Is Microsoft Copilot the New Clippy? Early Signs Raise Concern

Microsoft’s Copilot was supposed to revolutionize workplace productivity. Instead, six months after launch, adoption rates are raising alarms—and...

Elon Musk Defends Deep Fakes With Lawsuit

Elon Musk's social media platform, X (formerly Twitter), has filed a federal lawsuit challenging Minnesota's 2023 law that...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways