The latest generative AI models are not just stand-alone text-generating chatbots—instead, they can easily be hooked up to your data to give personalized answers to your questions. OpenAI’s ChatGPT can be linked to your Gmail inbox, allowed to inspect your GitHub code, or find appointments in your Microsoft calendar. But these connections have the potential to be abused—and researchers have shown it can take just a single “poisoned” document to do so.
New findings from security researchers Michael Bargury and Tamir Ishay Sharbat, revealed at the Black Hat hacker conference in Las Vegas today, show how a weakness in OpenAI’s Connectors allowed sensitive information to be extracted from a Google Drive account using an indirect prompt injection attack. In a demonstration of the attack, dubbed AgentFlayer, Bargury shows how it was possible to extract developer secrets, in the form of API keys, that were stored in a demonstration Drive account.
The vulnerability highlights how connecting AI models to external systems and sharing more data across them increases the potential attack surface for malicious hackers and potentially multiplies the ways where vulnerabilities may be introduced.
“There is nothing the user needs to do to be compromised, and there is nothing the user needs to do for the data to go out,” Bargury, the CTO at security firm Zenity, tells WIRED. “We’ve shown this is completely zero-click; we just need your email, we share the document with you, and that’s it. So yes, this is very, very bad,” Bargury says.
OpenAI did not immediately respond to WIRED’s request for comment about the vulnerability in Connectors. The company introduced Connectors for ChatGPT as a beta feature earlier this year, and its website lists at least 17 different services that can be linked up with its accounts. It says the system allows you to “bring your tools and data into ChatGPT” and “search files, pull live data, and reference content right in the chat.”
Bargury says he reported the findings to OpenAI earlier this year and that the company quickly introduced mitigations to prevent the technique he used to extract data via Connectors. The way the attack works means only a limited amount of data could be extracted at once—full documents could not be removed as part of the attack.
“While this issue isn’t specific to Google, it illustrates why developing robust protections against prompt injection attacks is important,” says Andy Wen, senior director of security product management at Google Workspace, pointing to the company’s recently enhanced AI security measures.
Source link
#Single #Poisoned #Document #Leak #Secret #Data #ChatGPT
![The Pope’s AI Warning Could Help Workers Seek Religious Exemptions From Using AI
Pope Leo XIV’s recent encyclical on AI could set off a wave of workers seeking religious exemptions from using the tech at work. One software engineer in North Carolina already secured one last month, Business Insider reports. Erin Maus, a Unitarian Universalist, first sought the accommodation in April at the large tech-entertainment company where she works, which she described as progressive. She argued that using AI did not align with her religious beliefs because of environmental and ethical concerns. Maus was granted the exemption in May, before the pope’s AI remarks. “I’m writing my code and reviewing my code by hand, which seems crazy to say,” Maus told Business Insider. “Just two years ago, how else would you do it?”
Maus is unlikely to be the only person seeking a similar accommodation as companies increasingly invest in AI and push, sometimes even mandate, employees to use the technology. In the U.S., the share of employees who say they use AI at least a few times a year at work has nearly doubled from 21% to 40% in 2025, according to Gallup.
Now, the pope’s remarks and official theological document could give some workers a stronger argument. “In the era of artificial intelligence, when human dignity is threatened by new forms of dehumanization, ours is the pressing duty to remain profoundly human,” the pope wrote in his 43,000-word encyclical titled Magnifica Humanitas, published last month. He wrote that AI is dehumanizing society by reducing “the mystery of the person into data and performance” and called on the tech industry to avoid “the idolatry of profit that sacrifices the weak.”
The pope continued that “a slower pace in adopting AI does not mean opposing progress; instead, it is an exercise of responsible care for the human family.” That call for a slower adoption of AI could be enough for some workers to argue they should not be required to use it on the job. “When he’s speaking, he’s speaking as the pontiff—as a religious figure—so he’s raising these human dignity issues as religious issues, theological issues,” Jonathan Segal, an employment attorney and Duane Morris partner, told HR Brew this month. “I think it is inevitable that some employees will rely on this to say…I can’t use AI because it conflicts with a religious belief that I have.” Under Title VII of the Civil Rights Act of 1964, employers are required to make reasonable accommodations for workers whose sincerely held religious beliefs conflict with a work requirement, unless the accommodation creates an undue hardship for the employer.
And it’s not a stretch to think some of these requests could at least get serious consideration. Just a few months ago, Rex Healthcare agreed to pay $150,000 to settle a lawsuit from the U.S. Equal Employment Opportunity Commission accusing the company of unlawfully denying a remote employee’s request to be exempted from its mandatory COVID-19 vaccine policy over religious beliefs. “I think this opens a door—or it’s a little bit of a road map—for employees to raise concerns,” Segal told HR Brew. “What the courts have said—what the EEOC has most definitely said—is that, as the general proposition, we shouldn’t question the legitimacy [of] sincerely held religious beliefs.” #Popes #Warning #Workers #Seek #Religious #ExemptionsAI,Pope Leo XIV,work The Pope’s AI Warning Could Help Workers Seek Religious Exemptions From Using AI
Pope Leo XIV’s recent encyclical on AI could set off a wave of workers seeking religious exemptions from using the tech at work. One software engineer in North Carolina already secured one last month, Business Insider reports. Erin Maus, a Unitarian Universalist, first sought the accommodation in April at the large tech-entertainment company where she works, which she described as progressive. She argued that using AI did not align with her religious beliefs because of environmental and ethical concerns. Maus was granted the exemption in May, before the pope’s AI remarks. “I’m writing my code and reviewing my code by hand, which seems crazy to say,” Maus told Business Insider. “Just two years ago, how else would you do it?”
Maus is unlikely to be the only person seeking a similar accommodation as companies increasingly invest in AI and push, sometimes even mandate, employees to use the technology. In the U.S., the share of employees who say they use AI at least a few times a year at work has nearly doubled from 21% to 40% in 2025, according to Gallup.
Now, the pope’s remarks and official theological document could give some workers a stronger argument. “In the era of artificial intelligence, when human dignity is threatened by new forms of dehumanization, ours is the pressing duty to remain profoundly human,” the pope wrote in his 43,000-word encyclical titled Magnifica Humanitas, published last month. He wrote that AI is dehumanizing society by reducing “the mystery of the person into data and performance” and called on the tech industry to avoid “the idolatry of profit that sacrifices the weak.”
The pope continued that “a slower pace in adopting AI does not mean opposing progress; instead, it is an exercise of responsible care for the human family.” That call for a slower adoption of AI could be enough for some workers to argue they should not be required to use it on the job. “When he’s speaking, he’s speaking as the pontiff—as a religious figure—so he’s raising these human dignity issues as religious issues, theological issues,” Jonathan Segal, an employment attorney and Duane Morris partner, told HR Brew this month. “I think it is inevitable that some employees will rely on this to say…I can’t use AI because it conflicts with a religious belief that I have.” Under Title VII of the Civil Rights Act of 1964, employers are required to make reasonable accommodations for workers whose sincerely held religious beliefs conflict with a work requirement, unless the accommodation creates an undue hardship for the employer.
And it’s not a stretch to think some of these requests could at least get serious consideration. Just a few months ago, Rex Healthcare agreed to pay $150,000 to settle a lawsuit from the U.S. Equal Employment Opportunity Commission accusing the company of unlawfully denying a remote employee’s request to be exempted from its mandatory COVID-19 vaccine policy over religious beliefs. “I think this opens a door—or it’s a little bit of a road map—for employees to raise concerns,” Segal told HR Brew. “What the courts have said—what the EEOC has most definitely said—is that, as the general proposition, we shouldn’t question the legitimacy [of] sincerely held religious beliefs.” #Popes #Warning #Workers #Seek #Religious #ExemptionsAI,Pope Leo XIV,work](https://gizmodo.com/app/uploads/2026/05/shutterstock_2666910201-1280x853.jpg)

Post Comment