Major Vulnerability Discovered in GPT-4 API: A Single Prompt Can Extract Private Information


DeepSeek's new API beta features revolutionary agent upgrades. Benchmark scores exceed its preview version. Developer tests show it efficiently completes complex tasks in ~40 seconds, significantly outperforming top overseas large models with robust overall capability.....
OpenAI plans to integrate ChatGPT AI into wearables, especially smart glasses, and will offer APIs for third-party integration, Brockman said in New York.....
The AI agent tool Claude Cowork from Anthropic has been exposed to a critical vulnerability that allows attackers to bypass the Linux virtual machine sandbox and read/write any files on Macs, affecting approximately 500,000 macOS users and potentially stealing login credentials. The tool previously required user authorization to access local files, but now both layers of security have been breached.
ChatGPT had a security vulnerability where attackers could use prompt injection and path traversal to bypass file access restrictions and obtain unauthorized data. The flaw stemmed from mishandling of uploaded files: while the system didn't offer raw file downloads, the exploit allowed stealing extra information. OpenAI has fixed it.....
Smart homes and voice assistants have become new targets for hackers. SafeBreach revealed a hidden vulnerability in Google Gemini, allowing hackers to send malicious notifications via WhatsApp or SMS, tricking the voice assistant into performing unauthorized actions, potentially taking over smart homes or altering contact lists. This threat is named "Pseudo-Context Alignment".