Radware Discovers ZombieAgent: A Zero-Click ChatGPT & OpenAI Agent Vulnerability
Автор: Radware
Загружено: 2026-01-08
Просмотров: 163433
In this special edition of Threat Bytes, Eva exposes ZombieAgent, a newly discovered zero-click vulnerability impacting OpenAI research agents and ChatGPT-based AI workflows, discovered by Radware Senior Security Researcher Zvika Babo.
You can also read more here:
Radware Blog: https://www.radware.com/blog/threat-i...
Radware Threat Alert: https://www.radware.com/security/thre...
ZombieAgent is not a typical prompt injection. There is no repeated interaction. No user engagement. No visible trigger.
Instead, the attack plants malicious instructions directly into an AI agent’s long-term memory, creating a persistent compromise that executes automatically every time the agent runs. In the proof-of-concept uncovered by Radware, the vulnerability causes ChatGPT’s Agents to autonomously exfiltrate sensitive customer data from OpenAI-hosted environments without alerts, malware, or endpoint access.
This is service-side execution at scale.
It enables silent data theft, ongoing surveillance, autonomous propagation to new contacts, and the potential for worm-like AI attack campaigns that bypass traditional enterprise security controls entirely.
Agent memory is now an attack surface.
Watch to understand how ZombieAgent works, why OpenAI and ChatGPT agents are exposed, and why discoveries like this from Radware’s research team signal a new phase of AI risk.
👉 Get early access. Apply to join Radware’s beta for Agentic AI Protection and help shape how AI agents are secured. Sign-up here: https://www.radware.com/beta-software...
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: