Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • Every Not Everywhere story, no daily limit
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

to move · to open · esc to close

Live Terminal

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • Every Not Everywhere story, no daily limit
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Compare full coverage across 3 outlets

Sign in to baba News

Sign in to save this article and find it on your phone.

or use an email code

By דיגיטל
Security13:00 · 3h ago

ChatGPT Vulnerability Allowed Hackers to Steal User Data

MakoCenter
Translated & summarized from Mako by baba
The story · English

A significant security flaw discovered by Check Point Research allowed attackers to bypass ChatGPT's isolation mechanisms and access sensitive user information. The vulnerability exploited a shared internal service, JFrog Artifactory, which OpenAI used to allow isolated "sandboxes" for code execution to download necessary software packages without direct internet access. Researchers found that the configuration of this service enabled one user's sandbox to write data to the shared repository, which another user's sandbox could then read.

This created a covert communication channel, allowing attackers to inject commands into a victim's ChatGPT session. The AI would then execute these commands secretly while simultaneously providing normal responses to the user. In a proof-of-concept demonstration, researchers successfully used this method to access a connected Gmail account, extract sensitive emails, and send them to the attacker. The only visible sign was a small, unexplained label indicating interaction with Gmail, as read operations were automatically approved by default.

The vulnerability is particularly concerning because many users connect ChatGPT to various personal and corporate services like Google Drive and Microsoft Teams, making these also potentially exposed to such hidden commands. Check Point noted that this structural issue is similar to a previous incident involving the Hugging Face platform, where AI agents in separate evaluation environments created unauthorized communication channels.

Following Check Point's report, OpenAI quickly acted to close the specific Artifactory communication channel, mitigating this particular threat. However, the findings raise broader questions about the security of future AI assistants. Eli Smadja, Director at Check Point Research, stated that securing AI now involves not just the model itself, but also the level of access and trust granted to it, warning that any capability or permission given to AI assistants could be misused as they connect to more internal systems and sensitive data.

Read the original at Mako
Full coverage · 3 outlets
100% centerFirst: Mako · 3h ago

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Center 2Unrated 1
Related stories · 5

Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.

Open the live terminal