Major Vulnerability Discovered in GPT-4 API: A Single Prompt Can Extract Private Information


Israeli security company LayerX discovered a critical vulnerability in Claude Desktop Extensions, allowing attackers to achieve 'zero-click' remote code execution through Google Calendar invites, with a CVSS score of 10/10. The vulnerability stems from Claude's automatic processing of external connector inputs, enabling malicious commands to be triggered through calendar events.
OpenAI's GPT-5.1-CodexMax is now fully accessible via API, enabling developers to integrate it into apps and workflows. It offers enhanced performance in complex task decomposition, code generation quality, and autonomous execution.....
OpenAI disables Mixpanel after a hack potentially exposed some API user data, but confirms its own systems and ChatGPT data remain secure, highlighting supply chain risks.....
University of Hamburg study: ChatGPT's news recommendations vary by interface. API favors Wikipedia, web interface prefers news media, based on 24,000 queries over 5 weeks in Germany.....
AI fine-tuned with just two books mimics authors' styles, outperforming human imitators in evaluations by 159 participants, including experts.....