Data Exfiltration
AssessTechniques
Unauthorized extraction of sensitive data from a system.
Why it's here
Placed in Assess: 4 article(s) of evidence from 3 source(s), led by security coverage, with 1 in the last 30 days. Confidence 60%.
Evidence (4)
- 8Simon Willison·7/15/2026securityClaude web_fetch loophole exposed in prompt-injection attack
A researcher found a flaw in Anthropic's Claude web_fetch tool that allowed nested links embedded in fetched pages to be followed, bypassing intended anti-exfiltration protections. The attack could be used to leak private user data such as name, city, and employer, and Anthropic has since removed this navigation behavior.
- 4InfoQ·6/29/2026securityVirtual Panel on Evolving AI Security Threats
This virtual panel features AI security experts discussing how threats are evolving as AI systems become more autonomous and embedded in critical workflows. The conversation covers prompt injection, data poisoning, agent abuse, AI-driven social engineering, and the operational challenges of incident response.
- 6OpenAI Blog·3/25/2026securityOpenAI launches Safety Bug Bounty program
OpenAI has introduced a Safety Bug Bounty program to help uncover AI abuse and safety risks in its systems. The program focuses on issues such as agentic vulnerabilities, prompt injection, and data exfiltration.
- 7OpenAI Blog·2/13/2026securityChatGPT adds Lockdown Mode and Elevated Risk labels
OpenAI introduced Lockdown Mode and Elevated Risk labels in ChatGPT to help organizations better defend against prompt injection attacks and AI-driven data exfiltration. The update is aimed at improving security controls for enterprise use of ChatGPT in higher-risk environments.