OpenAI patches ChatGPT flaw that smuggled data over DNS

2026-03-31T07:23:56Z9f516f554e0f5b673fc4634977e213af16bdd5819febabda5b4b9b696ccbe35a
ai-supply-chainapi-keys-exposedchatgptcitrix-netscalercredential-stealerdark-web-monitoringdata-breachdns-exfiltrationeuropean-commissionin-the-wild-exploitationlitellmopenaipoisoned-documentationpypisupply-chaintelnyxtrivyvoice-phishing

What happened

Multiple high-risk security incidents and supply-chain compromises were reported: OpenAI patched a ChatGPT flaw that allowed data exfiltration via a DNS side channel; the Trivy supply-chain compromise continues to ripple through ecosystems with malicious PyPI packages (LiteLLM, Telnyx) and credential-stealing payloads infecting 1,000+ cloud environments; a critical Citrix NetScaler vulnerability is being exploited in the wild days after disclosure; the European Commission confirmed attackers breached public web systems and siphoned data; AFC Ajax and other organizations disclosed breaches that

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
9f516f554e0f5b673fc4634977e213af16bdd5819febabda5b4b9b696ccbe35a
Enrichment time
2026-03-31T07:23:56Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · OpenAI patches ChatGPT flaw that smuggled data over DNS · Baitaphish