OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability
2026-03-31T01:24:11Z•ee316b7204f7827943b8c524d6d879333ab4fa4597249d880bc70ed0f23ee6e6
aitmchatgptclaude-extensioncodexcredential-theftctrl-toolkitdarksworddata-exfiltrationdeeploadgenielockerios-exploitlangchainlanggraphllm-securitymalwarenation-state-activityphishingpypiransomwarerdp-hijackred-menshensupply-chainteampcptelecom-espionagewebrtc-skimmer
What happened
This news roundup highlights multiple high-impact security issues and active campaigns: Check Point disclosed a ChatGPT prompt-based data-exfiltration flaw (and a Codex GitHub token issue) that allowed covert leakage of conversations and uploaded files; LangChain/LangGraph and Anthropic Claude extension flaws exposed files, secrets and allowed zero-click prompt injection; and TeamPCP pushed malicious Telnyx packages to PyPI as a supply-chain credential stealer. Multiple malware and targeted campaigns are active (DeepLoad loader using ClickFix and WMI persistence to harvest browser credentials,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- ee316b7204f7827943b8c524d6d879333ab4fa4597249d880bc70ed0f23ee6e6
- Enrichment time
- 2026-03-31T01:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.