This ‘ZombieAgent’ zero-click vulnerability allows for silent account takeover – here’s what we know


  • OpenAI’s new “apps” feature allows ChatGPT to connect to external services such as email and storage
  • Radware discovered “ZombieAgent”, a prompt injection flaw that allows hidden commands to exfiltrate or propagate data
  • Exploits include zero-click, one-click, persistence, and worm-like propagation; OpenAI patched on December 16th

OpenAI recently introduced a new feature to ChatGPT, which unfortunately also puts users at risk of data exfiltration and persistent access.

In December 2025, a feature called Connectors finally moved out of beta and into general availability. This feature allows ChatGPT to connect to several other apps, such as calendars, cloud storage, email accounts, and the like – giving users more context and thus better and more relevant responses.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top