OpenAI patches ChatGPT flaw that smuggled data over DNS
2026-03-31T07:23:56Z•9f516f554e0f5b673fc4634977e213af16bdd5819febabda5b4b9b696ccbe35a
ai-supply-chainapi-keys-exposedchatgptcitrix-netscalercredential-stealerdark-web-monitoringdata-breachdns-exfiltrationeuropean-commissionin-the-wild-exploitationlitellmopenaipoisoned-documentationpypisupply-chaintelnyxtrivyvoice-phishing
What happened
Multiple high-risk security incidents and supply-chain compromises were reported: OpenAI patched a ChatGPT flaw that allowed data exfiltration via a DNS side channel; the Trivy supply-chain compromise continues to ripple through ecosystems with malicious PyPI packages (LiteLLM, Telnyx) and credential-stealing payloads infecting 1,000+ cloud environments; a critical Citrix NetScaler vulnerability is being exploited in the wild days after disclosure; the European Commission confirmed attackers breached public web systems and siphoned data; AFC Ajax and other organizations disclosed breaches that
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 9f516f554e0f5b673fc4634977e213af16bdd5819febabda5b4b9b696ccbe35a
- Enrichment time
- 2026-03-31T07:23:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.