Radware Discovers ShadowLeak: The First Zero-Click, Server-Side Vulnerability in ChatGPT

Radware® (NASDAQ: RDWR), a leading provider of cybersecurity and application protection solutions, has uncovered a groundbreaking vulnerability called ShadowLeak, targeting the ChatGPT Deep Research agent. This zero-click, server-side exploit allows attackers to exfiltrate sensitive data without any user interaction, marking a new era of threats for enterprises adopting AI technologies.


Risks for Enterprises

The discovery highlights a new class of threats emerging with the large-scale adoption of AI agents in enterprises. As emphasized by Pascal Geenens, Director of Cyber Threat Intelligence at Radware, built-in safeguards alone are not sufficient. The combination of AI autonomy, SaaS services, and access to sensitive data introduces new risks that traditional security tools are unable to detect.


According to CNBC, ChatGPT currently has more than 5 million paying business users, significantly increasing the potential impact of such attacks


Responsible Disclosure and Response

Radware reported the vulnerability to OpenAI on June 18, 2025. OpenAI confirmed the issue and released a fix on September 3, 2025. Radware commended OpenAI’s swift response and collaboration in addressing the incident.


 


Radware is also preparing a live webinar on October 16, 2025, titled: “ShadowLeak: A Deep Dive into the First Zero-Click, Server-Side Vulnerability in ChatGPT.”


During the session, experts will provide a detailed explanation of the attack, recommend best practices for securing AI agents, and share insights into the future of responsible AI threat research.

 

More news

TrendAI™: Practical tips to get the most out of the platform

The transformation of Trend Micro into TrendAI™ brings a new perspective to cybersecurity, more automation, more AI, and a stronger focus on…

AI as the Biggest Security Threat: Key Insights from the Thales Data Threat Report 2026

Digital transformation is accelerating, but security is falling behind. Companies are rapidly adopting cloud technologies and AI, while simultaneously losing control over…

Important Changes in the RSA License Renewal Process

RSA Security is transitioning to an auto-renewal process designed to ensure smooth operations and continuous security coverage without the risk of service…