menu
techminis

A naukri.com initiative

google-web-stories
source image

Securityaffairs

2w

read

387

img
dot

Image Credit: Securityaffairs

ChatGPT SSRF bug quickly becomes a favorite attack vector

  • Threat actors exploit a server-side request forgery (SSRF) flaw, tracked as CVE-2024-27564, in ChatGPT, to target US financial and government organizations.
  • The SSRF vulnerability exists in the pictureproxy.php file of ChatGPT, allowing attackers to inject crafted URLs and make arbitrary requests.
  • Veriti researchers noted over 10,000 attack attempts within a week, primarily targeting government organizations in the US.
  • Misconfigured Intrusion Prevention Systems and Web Application Firewalls left 35% of the analyzed companies unprotected.

Read Full Article

like

23 Likes

For uninterrupted reading, download the app