Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories (in the app)
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the monthly limit

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

to move · to open · esc to close

Live Terminal

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories (in the app)
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the monthly limit

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Security00:07 · Sep 18

Sophisticated Phishing Attack Targets ChatGPT Users

By קובי ברקת
Translated & summarized from Behadrei Haredim by baba
The story · English

A new phishing campaign is exploiting the popularity of ChatGPT to steal user login credentials. According to cybersecurity firm Cofense, victims receive emails that appear to be billing notifications from OpenAI. These emails warn users that they must update their payment information within 48 hours, often citing a balance of $23.80 and including a button to update payment details.

The emails are not from OpenAI. The link, initially routed through Google APIs, leads to a malicious website designed to mimic ChatGPT's login screen. Users who enter their credentials on this fake page are not logging into ChatGPT; instead, their information is sent to the attackers, and they are then redirected to an error page.

Cofense cautions that the presence of a Google API address in a link does not guarantee its safety. This attack does not involve a breach of OpenAI's systems but rather a social engineering tactic to trick users into voluntarily surrendering their account details. OpenAI advises users who receive suspicious billing notices to log into their ChatGPT account directly through the official website and check their billing settings, rather than clicking on links in emails.

For users concerned about compromised passwords, OpenAI recommends immediately changing their password, logging out of all devices, and enabling multi-factor authentication.

Read the original at Behadrei Haredim
Open the live terminal