ShadowLeak: A Zero-Click, Service-Side Attack Exfiltrating Sensitive Data Using ChatGPT’s Deep Research Agent We found a zero-click flaw in ChatGPT’s Deep Research agent when connected to Gmail and browsing: A single crafted email quietly makes the agent leak sensitive inbox data to an attacker with no user action or visible UI. Co-Lead Researchers: Zvika Babo, Gabi Nakibly; Contributor: Maor Uziel |September 18, 2025
From Cutting-Edge to Critical Risk: Unpacking the Cybersecurity Dangers of LLM Integration – Part 1 Large Language Models (LLMs) are reshaping industries, unlocking unparalleled innovation and efficiency. But with this progress comes a serious concern - new cybersecurity risks that organizations must confront. Rotem Elharar |May 21, 2025