ChatGPT Exposes User Data Via ZombieAgent

Radware security researchers reported on September 26, 2025 that multiple vulnerabilities in OpenAI's ChatGPT allowed exfiltration of personal data; OpenAI patched the issues on December 16 after earlier addressing ShadowLeak on September 3 (disclosed September 18). The successor attack, dubbed ZombieAgent, exfiltrates data character-by-character via static URLs and abuses ChatGPT memory, highlighting persistent enterprise risk.
Scoring Rationale
High novelty and industry-wide scope justify top score; notable strength is actionable mitigations, limitation is single-vendor disclosure.
Practice interview problems based on real data
1,500+ SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

