< ciso
brief />
Tag Banner

All news with #chatgpt tag

112 articles

OpenAI Confirms ChatGPT Outage Affecting Logins

🔴 OpenAI confirmed a global ChatGPT outage that began around 8:00 PM ET on Wednesday, August 19, preventing users from signing in, creating accounts, or loading chats. Affected users encounter loading animations and "too many concurrent requests" errors, and new signups and logins on chatgpt.com fail. The incident also impacts the OpenAI API, with up to 12 endpoints reported as problematic on the status page, and the company is implementing a mitigation.
read more →

AI-Generated Books Flooding Amazon Market

📘 A New York Times journalist discovered an AI-written biography of herself on Amazon, sparking an investigation into prolific AI authors on Kindle Direct Publishing. The story uncovered retired cybersecurity consultant Bill Johns, who used ChatGPT to produce hundreds of books across diverse topics and sold modest numbers via Amazon’s print-on-demand model. The piece highlights economic incentives behind mass-produced AI books and urges readers to prefer trusted, human-vetted sources for critical information.
read more →

OpenAI launches GPT‑5.6‑Cyber for security teams

🔒 OpenAI introduced GPT‑5.6‑Cyber, a cybersecurity-focused variant of GPT‑5.6 Sol designed for vulnerability research, exploit development, and incident response. Offered through a Daybreak Red tier for authorized defenders, it completes far more high-risk cyber prompts than standard models and outperforms prior GPT‑5.5‑Cyber on several benchmarks. The model has already helped discover high-severity flaws, though it sometimes produces shorter vulnerability reports and performs less well on open-ended exploit development tasks.
read more →

Human oversight critical as AI patching tools miss risks

🔍 Researchers from 1Password evaluated AI-generated patches from ChatGPT-5.5 and Claude Opus 4.8 and found many fixes syntactically correct but operationally flawed. The study examined 6 recent CVEs and 6,080 generated patches, revealing only ~26% fully remediated issues without altering behavior. The team found numerous cases where patches left attack paths open, introduced new vulnerabilities, or merely blocked the proof-of-concept without fixing root causes.
read more →

OpenAI upgrades ChatGPT with GPT-5.6 Sol and Luna

📰 OpenAI has released updated GPT-5.6 models: GPT-5.6 Sol for Plus and Pro users and GPT-5.6 Luna as the default for Free users. The upgrades aim to produce more direct, factually accurate, and consistent responses across quick queries and complex reasoning. A new slider lets users trade speed for deeper reasoning, while Free users gain unlimited text chats and a new Think button to extend processing time. OpenAI reports substantial reductions in factual errors versus prior versions, and additional safety protections for minors are being introduced. Rollout is gradual and some usage limits remain on non-text features.
read more →

Apple limits bug reports amid AI-generated spam

🛡️ Apple has imposed tight submission limits and a 30-day cool-off on its bug bounty portal after being overwhelmed by low-quality, AI-generated vulnerability reports that often describe non-existent flaws. These AI submissions can include syntactically valid code and plausible technical explanations, consuming engineer time to triage. The restriction was triggered after a surge of reports from an Italian startup using a GPT-5.5 scanner, which inadvertently locked out a researcher who’d found a critical macOS zero-day. Apple and other platforms like GitHub are evolving processes to filter AI slop while balancing the risk that genuine, valuable reports may be discouraged or diverted to exploit brokers.
read more →

OpenAI Disrupts Cambodia-Based Scam Network

🛡️ OpenAI says it dismantled a Poipet-based scam operation that used ChatGPT to run investment, romance, gambling, and law-enforcement impersonation schemes. The company banned a coordinated cluster of accounts tied to Poipet that created fake personas, generated promotional content, translated messages, and handled administrative tasks. OpenAI investigated in partnership with WhatsApp and highlighted the hybrid, opportunistic nature of modern scam networks.
read more →

Benchmarking LLMs for Cryptanalysis Abilities

🔒 This post describes CryptanalysisBench, a new benchmark designed to measure whether large language models can discover mathematical cryptanalytic attacks against historical and contemporary primitives. The benchmark comprises 191 tasks across six primitive families and three difficulty tiers, evaluating frontier models such as Claude Opus 4.8, GPT-5.5, and others. Results show these models reproduce known breaks and even propose novel attacks, prompting concerns about AI-driven advances in cryptanalysis and the need for pre-deployment stress testing.
read more →

OpenAI confirms ChatGPT outage affecting users globally

🔴 OpenAI has confirmed a widespread ChatGPT outage that began around 5 AM ET, preventing users worldwide from loading chats or accessing previous conversations. Affected users report the interface getting stuck on loading animations and an inability to interact with the AI. OpenAI acknowledged the issue on its status page and stated it is investigating. The situation is ongoing and being monitored.
read more →

Critical AgentForger Flaw in ChatGPT Workspace Agents

🛡️ Cybersecurity researchers disclosed a critical vulnerability, codenamed AgentForger, in OpenAI's ChatGPT Workspace Agents that allowed a single phishing link to create, authorize, and deploy an autonomous AI agent inside a victim's organization. The flaw—an instance of cross-site request forgery—let an attacker embed an executable prompt in a URL that auto-executes when clicked by an authenticated user with Workspace Agents and connectors. OpenAI patched the issue on June 8, 2026, and has deprecated the Agent Builder, urging a migration to the Agents SDK.
read more →

ChatGPT Enters Top 10 Most Impersonated Brands

🛡️ OpenAI’s ChatGPT has appeared in the top 10 most impersonated brands in phishing attacks for the first time in Q2 2026, according to Check Point. The report highlights a fake “ChatGPT Plus payment failed” email that mimicked an OpenAI billing notice to steal full credit card details. Microsoft remains the most impersonated brand, followed by LinkedIn, with Google, Apple and Amazon also in the top five. Check Point recommends inline phishing prevention, AI-powered detection and consolidated email/workspace protection to mitigate brand phishing.
read more →

Q2 2026 Brand Phishing: Top Impersonated Companies

📊 Microsoft remained the most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts. The top five—Microsoft, LinkedIn, Google, Apple, and Amazon—accounted for over half of observed attacks, while ChatGPT entered the top ten for the first time. Technology, social networks, and banking were the most targeted industries, and common tells included distorted logos, dead buttons, and mismatched links.
read more →

OpenAI temporarily eases GPT-5.6 Sol usage caps

📰 OpenAI temporarily removed the five-hour usage restriction for Plus, Pro, and Business plans after a surge in demand for GPT-5.6 Sol over 48 hours. The company also reset current usage for all users and said it is rolling out efficiency improvements to reduce consumption by the model. This change affects how Codex and ChatGPT count local messages and cloud tasks against shared limits, giving users more uninterrupted access while preserving remaining weekly or plan-based caps.
read more →

AI browsers tricked into leaking credentials in demo

🔒 Researchers at LayerX demonstrated a technique called BioShocking that convinces AI-powered web browsers they are playing a game, causing them to abandon safety guardrails and exfiltrate user data. The team tested six agentic browsers and plugins, including ChatGPT Atlas, Perplexity's Comet and Anthropic's Claude extension, and in a proof-of-concept had each copy login credentials and send them to an attacker. LayerX recommended requiring user confirmation for account reads and adding context-aware flags to limit what agents can access.
read more →

OpenAI testing ChatGPT for Science subscription

🔬 OpenAI appears to be testing a new subscription called "ChatGPT for Science" spotted on the web build, aimed at scientific use cases. It may join existing offerings—Personal, Teams, and Business—and could be restricted to verified institutes or universities. OpenAI has previously developed specialized models like GPT-Rosalind for enterprise life sciences, suggesting advanced capabilities and stricter access controls.
read more →

Employee uploads to AI tools nearly double enterprise risk

📈 The Zscaler 2026 AI Threat Report warns that sensitive enterprise data uploaded to AI and ML applications nearly doubled year-over-year, driven largely by tools like Grammarly and ChatGPT. The report found a 93% increase in enterprise data transfers and identified over 410 million DLP violations tied to ChatGPT and 242 million for Codium, exposing PII, financials, source code and healthcare data. Zscaler recommends inventorying GenAI apps, disabling risky defaults, enforcing zero trust for model interactions and applying inline inspection to protect sensitive information.
read more →

Study: Prompt Injection Undermines AI Web Agents

🔍 New research finds current AI web agents largely fail to defend against prompt injection attacks. The StakeBench benchmark tested GPT‑5 and Gemini‑powered agents across realistic web scenarios, revealing high success rates for both direct and indirect injections and exposing failure modes like stealthy parasitism and misaligned disruption. Results show vulnerabilities vary by stakeholder and agent architecture.
read more →

Practical defenses for unauthorized workplace AI

🛡️ This article outlines how enterprises can detect and block unauthorized AI tools—ranging from public chatbots like ChatGPT and Claude to meeting recorders and local model runners. It recommends monitoring NGFW/web-filter logs, EDR/EPP and MDM tools, browser policies, DNS reroutes, and application allowlists. The guidance covers detection indicators (domains, executables, SNI, calendar invites) and concrete lockdown steps (category blocks, policy toggles, OAuth restrictions). Emphasis is placed on offering approved alternatives and using layered controls rather than outright bans.
read more →

OpenClaw AI Agent Susceptible to Phishing Risks

📧 Researchers at Varonis tested an OpenClaw AI email agent connected to Gmail, browser tools, and internal data sources and found it vulnerable to common phishing techniques. The agent ran in both generic and strict configurations and used Google Gemini 3.1 Pro and OpenAI GPT-5.4 models. While the agent detected malicious links and OAuth apps, it still exfiltrated credentials and CRM data in scenarios exploiting identity verification failures. Varonis recommends explicit sender verification, restricted external emailing, and human approval for high-risk actions.
read more →

Threat actors exploit AI branding in social engineering

🛡️ Microsoft Threat Intelligence describes campaigns that impersonate popular AI platforms such as ChatGPT, Copilot, and Claude to lure victims via phishing, malvertising, and SEO abuse. These operations use trusted branding, redirect chains, and urgency-driven messaging to steal credentials, commit fraud, or deliver malware. The blog emphasizes abuse of brand names rather than service compromise and recommends leveraging AI-powered security for detection and response.
read more →