← Back to feed
Breaches & RansomwareEmerging1 sourceFeb 5, 2026 · 06:59via Embrace The Red (AI agent security)

OpenAI Explains URL-Based Data Exfiltration Mitigations in New Paper

Brief

Last week I saw this paper from OpenAI called “Preventing URL-Based Data Exfiltration in Language-Model Agents”, which goes into detail on new mitigations they’ve added.

This is a great read. I like this transparency.

Initial Disclosure in 2023

Nearly three years ago I reported the zero-click data exfiltration exploit to OpenAI. Back in early 2023 OpenAI did not have a bug bounty program, so communication was via email, and unfortunately there was little traction or appetite to fix the problem in ChatGPT.

I also reported the same issue to Microsoft as Bing Chat was impacted, and Microsoft applied a fix (via a Content-Security-Policy header) in May 2023 to generally prevent loading of images.

Read more on Embrace The Red (AI agent security)