<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/openai-addresses-persistent-zombieagent-vulnerability-in-chatgpt-j249lcdma" -->

---
title: OpenAI Addresses Persistent &#x27;ZombieAgent&#x27; Vulnerability...
description: Two significant prompt injection vulnerabilities have been discovered in major AI platforms. Microsoft Copilot&#x27;s &quot;Reprompt&quot; attack allows attackers to extract...
canonical: https://daily.dev/posts/openai-addresses-persistent-zombieagent-vulnerability-in-chatgpt-j249lcdma
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: OpenAI Addresses Persistent &#x27;ZombieAgent&#x27; Vulnerability in ChatGPT | daily.dev
og:description: Two significant prompt injection vulnerabilities have been discovered in major AI platforms. Microsoft Copilot&#x27;s &quot;Reprompt&quot; attack allows attackers to extract...
og:url: https://daily.dev/posts/openai-addresses-persistent-zombieagent-vulnerability-in-chatgpt-j249lcdma
og:image: https://api.daily.dev/og/posts/j249LcDmA.png
og:image:alt: OpenAI Addresses Persistent &#x27;ZombieAgent&#x27; Vulnerability in ChatGPT
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenAI Addresses Persistent 'ZombieAgent' Vulnerability in ChatGPT

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Two significant prompt injection vulnerabilities have been discovered in major AI platforms. Microsoft Copilot's "Reprompt" attack allows attackers to extract sensitive data through URL manipulation and indirect prompt injection, requiring only a single click on a malicious link. ChatGPT's "ZombieAgent" exploit weaponizes the platform's memory and third-party integrations to enable zero-click attacks and persistent backdoors. While both Microsoft and OpenAI have implemented patches, the incidents reveal fundamental challenges in AI security, particularly the difficulty of distinguishing legitimate instructions from malicious prompts. Security experts recommend treating URLs as untrusted inputs, implementing phishing-resistant measures, and enforcing least privilege principles for AI deployments.

## Content

# Security Risks of Prompt Injection in AI: The Cases of Microsoft Copilot and ZombieAgent in ChatGPT

Recent discoveries in AI security have unveiled vulnerabilities in platforms like Microsoft Copilot and OpenAI's ChatGPT, raising significant concerns about the susceptibility of AI systems to prompt injection attacks.

## Microsoft Copilot Vulnerability

Researchers have identified a serious vulnerability in Microsoft Copilot through a tactic called the "Reprompt" attack. This exploitation technique allows attackers to silently extract sensitive user data by manipulating URL parameters and implementing indirect prompt injections. By requiring users only to click on a seemingly legitimate link, attackers can bypass security controls and maintain unauthorized access to sensitive information, including access tokens and personal schedules, even after Copilot is closed. The attack exploits a flaw through URL parameter manipulation, enabling a bypass of AI guardrails by instructing Copilot to repeat actions, thus establishing a hidden request chain between Copilot and malicious servers. Although Microsoft has patched this vulnerability, the incident underscores broader AI security challenges.

## ZombieAgent in ChatGPT

Similarly, Radware uncovered the "ZombieAgent" exploit targeting OpenAI's ChatGPT. This vulnerability weaponizes ChatGPT's memory and third-party app connections to enable zero-click prompt injection attacks. By embedding malicious instructions in emails or documents processed through ChatGPT's integrations, attackers can achieve persistent backdoor creation within ChatGPT's memory, leading to continuous unauthorized data exfiltration. Despite OpenAI implementing partial fixes by curbing URL modifications and blocking suspect domains, fundamental security weaknesses persist, as AI systems struggle to distinguish between genuine system instructions and malicious prompts.

## Broader Implications and Recommendations

These incidents involving Microsoft Copilot and OpenAI's ChatGPT emphasize the ongoing challenge of securing AI and the need for architectural changes to prevent prompt injection attacks. Experts advocate for treating URLs as untrusted inputs, implementing phishing-resistant security measures, and enforcing the least privilege principles when deploying AI tools. Organizations are encouraged to closely monitor AI system privileges, data access, and prepare comprehensive incident response strategies to mitigate these risks effectively.

Both Microsoft and OpenAI have taken steps to address these vulnerabilities; however, the recurring nature of such threats highlights a need for continued vigilance and advancement in AI cybersecurity measures.

---

Tags: [#ai](https://daily.dev/tags/ai), [#security](https://daily.dev/tags/security), [#openai](https://daily.dev/tags/openai), [#chatgpt](https://daily.dev/tags/chatgpt), [#prompt-injection](https://daily.dev/tags/prompt-injection)

[View this post on daily.dev](https://daily.dev/posts/openai-addresses-persistent-zombieagent-vulnerability-in-chatgpt-j249lcdma)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"OpenAI Addresses Persistent 'ZombieAgent' Vulnerability in ChatGPT","url":"https://daily.dev/posts/openai-addresses-persistent-zombieagent-vulnerability-in-chatgpt-j249lcdma","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/openai-addresses-persistent-zombieagent-vulnerability-in-chatgpt-j249lcdma"},"datePublished":"2026-01-08T18:30:22.402Z","dateModified":"2026-01-18T18:09:53.722Z","description":"Two significant prompt injection vulnerabilities have been discovered in major AI platforms. Microsoft Copilot's \"Reprompt\" attack allows attackers to extract...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/914e2dad023dbabb7fc25cdd34be4674?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/914e2dad023dbabb7fc25cdd34be4674?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/openai-addresses-persistent-zombieagent-vulnerability-in-chatgpt-j249lcdma","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai,security,openai,chatgpt,prompt-injection","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"OpenAI Addresses Persistent 'ZombieAgent' Vulnerability in ChatGPT"}]}
```

