Hackers have figured out how a to look at everything you have been asking ChatGPT and see the answers.
Instead of attackers using ChatGPT to cause cyber attacks, they have turned the technology on itself. OpenAI, which developed the chatbot, confirmed a data breach of the system, according to Security Week. The breach took the service offline until it was fixed.
ChatGPT has quickly becameย the fastest-growing consumer appย in history, reaching over ๐๐๐ ๐ฆ๐ข๐ฅ๐ฅ๐ข๐จ๐ง ๐ฆ๐จ๐ง๐ญ๐ก๐ฅ๐ฒ ๐ฎ๐ฌ๐๐ซ๐ฌ by January. Approximately 13 million people used the AI technology daily within a full month of its release. Letโs compare that to another extremely popular app โ TikTok โ which took ๐ก๐๐ก๐ ๐ ๐ข๐ก๐ง๐๐ฆ to reach similar user numbers.
Anytime you have a popular app or technology, itโs only a matter of time until Hackers start targeting it. For ChatGPT, the exploit came via a vulnerability in the Redis open-source library. This allowed users to see the chat history of other active users.
Because thousands of contributors develop and have access to the open-sourceย code that makes up ChatGPT, itโs easy for vulnerabilities to go unnoticed. Hackers are very aware of this fact, which is why attacks on open-source libraries haveย increased by 742%ย since 2019.
The ChatGPT exploit has been classified as minor, and OpenAI was able to patch the bug within days. But we have to keep in mind even a minor cyber incident can create a lot of damage.
This was considered to be a ๐ฌ๐ฎ๐ซ๐๐๐๐-๐ฅ๐๐ฏ๐๐ฅ ๐ข๐ง๐๐ข๐๐๐ง๐ญ. But as researchers from OpenAI looked closer, they discovered the same vulnerability was likely responsible for Hackers being able to look at ๐๐ฎ๐ฌ๐ญ๐จ๐ฆ๐๐ซ ๐ฉ๐๐ฒ๐ฆ๐๐ง๐ญ ๐ข๐ง๐๐จ๐ซ๐ฆ๐๐ญ๐ข๐จ๐ง for a few hours before ChatGPT was taken offline.
โIt was possible for some users to see another active userโs first and last name, email address, payment address, the last four digits (only) of a credit card number and credit card expiration date. Full credit card numbers were not exposed at any time,โ OpenAI said in aย releaseย about the incident.
There are some potentially huge privacy concerns surrounding the use of chatbots. The AI technology stores vast amounts of data and then uses that information to generate responses to questions and prompts. And anything in the chatbotโs memory becomes fair game for other users.
For example, chatbots can record a single userโs notes on any topic and then summarize that information or search for more details. But if those notes include sensitive data โ an organizationโs intellectual property or sensitive customer information, for instance โ it enters the chatbot library. The person no longer has control over that information.
Because of these privacy concerns, some businesses and entire countries are restricting access or blocking it altogether.