10
you are viewing a single comment's thread
view the rest of the comments
[-] drspod@lemmy.ml 9 points 1 day ago

AFAICT this is not the OpenAI web interface, it's just a third-party web interface for ChatGPT that calls the OpenAI API and the author of this web interface called it just "ChatGPT".

Presumably the author of this article is incapable of actually doing the 2 minutes of research necessary to identify that this is not an official ChatGPT codebase that contains the vulnerability.

"hackread.com" ? Written by a hack, more like.

[-] satans_methpipe@lemmy.world 3 points 1 day ago

But the author bios says:

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.

Lol

[-] stevedice@sh.itjust.works 0 points 1 day ago* (last edited 1 day ago)

It is a bug in chatgpt that is being used to attack companies that rely on openAI's API. They point that out in the literal first paragraph of the article.

In its latest research report, cybersecurity firm Veriti has spotted active exploitation of a vulnerability within “OpenAI’s ChatGPT infrastructure” but there is no evidence that OpenAI itself has been breached.

I really don't know what is your problem.

[-] drspod@lemmy.ml 3 points 22 hours ago

I'm claiming that the article is wrong and you're quoting the article at me? Yes I know what the article says because I read it, and then researched the vulnerability.

The CVE is: https://nvd.nist.gov/vuln/detail/CVE-2024-27564

Which was described in an issue in GitHub here: https://github.com/dirk1983/chatgpt/issues/114

Which relates to this GitHub repository: https://github.com/dirk1983/chatgpt/

Which is by github user dirk1983, and if you read (translate) the readme, you will see that it's a ChatGPT front-end written by this user, not anything officially released by OpenAI.

The confusion comes from the fact that his repository (this front-end with the vulnerability) is just called "ChatGPT", and neither the journalist nor you did this basic search to find that out.

[-] Boomkop3@reddthat.com 2 points 1 day ago

Add them to the mute list :p

this post was submitted on 18 Mar 2025
10 points (81.2% liked)

Cybersecurity

6732 readers
231 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS