Researchers have discovered a new attack on ChatGPT that exploits vulnerabilities in the AI’s processing of input prompts. Attackers can skim sensitive user data and embed permanent instructions in the model’s memory. This latest vulnerability, dubbed ZombieAgent, represents a dangerous vicious cycle in which developers fix one bug only to create the next vulnerability.
Security experts warn that today’s protection mechanisms are mostly reactive rather than preventive. Large language models find it difficult to distinguish malicious inputs from legitimate commands, raising fundamental questions about the long-term security and trustworthiness of AI systems.