Three high-risk AI vulnerabilities discovered in Claude.ai – end-to-end attack chain exfiltrates sensitive info without user knowing



  • Oasis researchers uncover “Cloudy Day” attack chain in Claude
  • Exploits include invisible prompt injection, data exfiltration via API, and open redirects
  • Anthropic patched one flaw, fixes for remaining two underway

Security researchers Oasis recently found three vulnerabilities in Claude which, when used together, form a complete attack chain – from targeted victim delivery to sensitive data exfiltration.

The researchers dubbed it Cloudy Day and responsibly disclosed it to Anthropic.


https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img