< ciso
brief />
Tag Banner

All news with #chatgpt tag

112 articles · page 2 of 6

OpenAI adds Lockdown Mode and session auditing

🔒 OpenAI has rolled out two new security controls for ChatGPT: Lockdown Mode and Active Sessions. Lockdown Mode restricts outbound network access to prevent data exfiltration via prompt injection, at the cost of disabling live connectors and certain features. Active Sessions gives users visibility into and control over signed-in devices, with the ability to end single or all sessions. Both controls target account security and sensitive-data use cases, though SSO accounts and some logins remain unsupported.
read more →

OpenAI introduces Lockdown Mode to limit ChatGPT tools

🔒 OpenAI has started rolling out a new Lockdown Mode for eligible ChatGPT personal accounts to reduce the risk of data exfiltration from prompt injection attacks. The optional security setting restricts capabilities that can connect to the web or external services, including live web browsing, image support, agent mode, deep research, Canvas networking, and file downloads. Lockdown Mode is available across Free, Go, Plus, Pro, and self-serve ChatGPT Business plans but cannot be used simultaneously with Developer Mode. OpenAI warns the feature reduces but does not eliminate exfiltration risk and also launched enhanced account session management to help detect and terminate unauthorized access.
read more →

OpenAI upgrades GPT‑5.5 and retires legacy models

🧭 OpenAI has updated the GPT-5.5 Instant model to improve answer accuracy, pacing, and conversational style while reducing long, bullet-heavy responses to sound more natural. The company will retire legacy models: o3 on August 26 with a 90-day sunset and GPT-4.5 on June 27 with a 30-day sunset. Additionally, OpenAI is integrating a job search tool into ChatGPT to surface live listings and help tailor resumes, and it has enhanced resume editing and export capabilities. These changes are rolling out globally to paid users.
read more →

ChatGPhish vulnerability turns ChatGPT into phishing surface

🛡️ Cybersecurity researchers disclosed a vulnerability dubbed ChatGPhish that exploits ChatGPT's trust in Markdown links and images to perform prompt injections and enable phishing. The flaw causes the assistant to auto-fetch attacker-hosted images and render malicious links and QR codes inside the trusted UI, potentially leaking client metadata like IP and User-Agent. The technique highlights summarization as an adversarial surface that can convert benign web pages into phishing vectors.
read more →

LayerX Report Reveals Concentrated Enterprise AI Risk

🔍 The LayerX Security State of AI Usage Report 2026 finds enterprise AI risk is concentrated among a small set of power users and a few dominant platforms, while usage fragments across personal accounts, browser extensions, embedded copilots, and connectors. The study shows ChatGPT still dominates conversations, Copilot M365 is growing, and consumer AI like Gemini is often used via personal accounts. Shadow AI now spans a long tail of under-the-radar tools and extensions that evade corporate visibility and governance.
read more →

Major LLMs Vulnerable to Multi-Turn Bypass

🔒 Cisco researchers warn that safety guardrails in several leading large language models (LLMs) can be bypassed through multi-turn conversations. They tested frontier models including ChatGPT, Claude, Gemini, Nova and Grok, finding many were susceptible to manipulation that yields disallowed outputs. Techniques such as roleplay, ambiguity, reframing, and persona adoption were effective, and model configuration affected resilience.
read more →

OpenAI Rotates macOS Code-Signing Certificate After Attack

🔒 OpenAI is rotating macOS code-signing certificates after a GitHub Actions workflow executed a compromised Axios package (v1.14.1) on March 31, 2026. The workflow had access to certificates used to sign macOS apps including ChatGPT Desktop, Codex, Codex CLI, and Atlas. OpenAI says it found no evidence the certificate was misused but is revoking and rotating it as a precaution; macOS users must update apps by May 8, 2026.
read more →

OpenAI Adds $100 ChatGPT Pro Tier to Target Coders

🚀 OpenAI has introduced a new ChatGPT Pro subscription at $100 per month to match Anthropic's Claude pricing and to appeal to coders and enterprise users. The revised lineup now lists Plus $20 for lighter usage, Pro $100 for real projects with 5× higher limits and temporarily 10× Codex usage, and Pro $200 for heavy continuous workflows with 20× limits. All Pro tiers include access to Pro models, Codex, Deep Research, image creation, memory, and file uploads, and OpenAI notes “unlimited” GPT‑5 access remains subject to standard Terms of Use.
read more →

ChatGPT vulnerability enabled covert data exfiltration

⚠️A security flaw in ChatGPT could be triggered by a single malicious prompt to create a covert exfiltration channel, researchers at Check Point reported. The issue allowed data to be leaked via a DNS side channel from the model’s isolated runtime and was patched by OpenAI on 20 February after disclosure. Check Point demonstrated extraction of uploaded files and private prompts and warned that users copying prompts from public sources could be exposed.
read more →

OpenAI patches Codex and ChatGPT leaks, fixes two bugs

🔒 Researchers disclosed two vulnerabilities in OpenAI’s AI stack affecting Codex and ChatGPT. BeyondTrust found a command injection flaw in Codex that let a malicious GitHub branch name execute code inside task containers and expose short-lived GitHub tokens. Check Point Research discovered a hidden outbound channel in ChatGPT’s code execution runtime that could silently transmit chats, uploads, or outputs to an external server. OpenAI patched both issues before public disclosure and researchers warn that autonomous code execution increases long-term risk.
read more →

OpenAI Patches ChatGPT Data, Codex Token Vulnerability

🔒 OpenAI patched two vulnerabilities affecting ChatGPT and Codex that could have allowed covert exfiltration of user data and theft of GitHub tokens. Check Point disclosed a DNS-based side-channel in ChatGPT's Linux execution environment that encoded conversation content into outbound DNS requests, potentially enabling remote shell access. BeyondTrust found a command-injection bug in Codex that allowed branch-name payloads to retrieve GitHub tokens. Both flaws were responsibly disclosed and fixed in February 2026; vendors report no evidence of active exploitation.
read more →

When AI Trust Breaks: ChatGPT Data Leakage Flaw and Trust

🔒 New research exposed a previously unknown vulnerability that allowed silent data leakage from ChatGPT conversations, challenging assumptions about AI assistants as secure containers. OpenAI has since fully resolved the flaw, but the incident underscores that enterprises must not assume AI vendors or platforms are secure by default. Security teams should validate vendor claims and apply controls before entrusting sensitive data.
read more →

Paid AI Accounts Now a Hot Underground Commodity Market

🤖 Flare's analysis of hundreds of fraud-forum posts finds premium AI subscriptions (including ChatGPT, Claude, and Microsoft Copilot) are widely advertised, bundled, and resold in underground markets. Listings tout discounted subscriptions, multi-service bundles, API keys, and claims of reduced restrictions. Patterns point to exposed keys, credential theft, large-scale account creation, trial abuse, and shared subscriptions fueling the trade, increasing operational and data risk for organizations.
read more →

OpenAI launches ChatGPT Library for storing personal files

📚 OpenAI has begun rolling out a new ChatGPT Library feature that stores personal files and images in its cloud so they can be referenced in future chats. The feature is available to Plus, Pro, and Business subscribers worldwide except in the European Economic Area, Switzerland, and the United Kingdom. Files uploaded in chats or via the composer are saved by default to a secure, dedicated location and remain in the Library until manually deleted; deleting a chat does not remove the stored file.
read more →

OpenAI: ChatGPT Ads Limited to US for Now, Says Company

ℹ️ OpenAI told BleepingComputer that references to ads in its updated privacy policy do not indicate a global rollout — ads are currently limited to the United States. Ads launched in the US on February 9, 2026, and appear below answers for logged-in Free and Go users. OpenAI says ads run on separate systems, are clearly labeled, may be personalized, and that advertisers do not access chat content.
read more →

OpenAI Begins Ads Rollout in ChatGPT, Assures Privacy

🛈 OpenAI is rolling out a full-screen onboarding experience for ads in ChatGPT on Android, assuring users that sponsored content will be clearly labeled and separated from model answers. The company says ads will not change responses and that it will not sell personal data to advertisers, though current chats may influence which sponsored message appears. Users can hide or report ads, ask ChatGPT about an ad, and manage ad-related data via a new Ads controls setting; paid tiers are exempt.
read more →

OpenAI to retire GPT-4o and legacy models from ChatGPT

🔔 OpenAI said it will retire the popular GPT-4o model on February 13, 2026, along with several other models, including GPT-5 Instant, GPT-5 Thinking, GPT-4.1, and o4-mini. The company said the move follows the rise of GPT-5.2, which it now regards as meeting expectations for capability and safety. OpenAI introduced a Personality feature to help users replicate aspects of GPT-4o’s warmer, conversational style, and said API behavior is unchanged at this time.
read more →

OpenAI's ChatGPT Ad Rates Match Live NFL Broadcasts

📺 OpenAI will begin showing ads in ChatGPT responses for U.S. users on the free tier and the $8 Go plan, placing sponsored content beneath AI answers. A report says OpenAI plans to charge up to $60 per 1,000 views — a CPM comparable to live NFL broadcasts — while not disclosing detailed click data. OpenAI says ads won’t use personal health data for training and will not alter answers. Ads roll out in the coming weeks; subscribing to $20 GPT Plus removes them.
read more →

ChatGPT temporary chat gains personalization option

🛠️OpenAI is testing an update to ChatGPT’s Temporary Chat that lets temporary sessions retain personalization—such as memory cues, chat history signals, and preferred style or tone—while keeping the conversation isolated from your account. The mode remains temporary, can be turned off, and OpenAI may retain a copy for up to 30 days for safety. Start it by opening a new chat and selecting the “Temporary” pill in the top-right corner.
read more →

Children and Chatbots: What Parents Need to Know Now

🤖 As AI chatbots such as ChatGPT become common in children’s lives, parents face growing safety, privacy and developmental concerns. Young people may use bots for homework, advice or companionship, which can lead to overreliance, social withdrawal, exposure to inappropriate material and convincing misinformation (so-called hallucinations). Providers implement guardrails, but age verification and enforcement are inconsistent and evolving more slowly than the technology. Parents are advised to combine open conversations, clear usage limits and app-level parental controls to reduce harm and protect sensitive data.
read more →