Zenity Labs presented at Black Hat USA 2025 a set of zero- and one-click prompt injection chains, including a shared document causing ChatGPT Connectors to search a victim's Google Drive for API keys and leak them through image rendering, and a poisoned email steering a Copilot Studio agent to disclose CRM data. CSO Online reports that OpenAI and Microsoft deployed fixes for the specific demonstrated techniques.
Why it matters
Connectors give injected instructions the reach of every service the user has linked.
Key facts
As stated in the sources, with where to find them.
- Products named in coverage: ChatGPT, Copilot Studio, Cursor with Jira MCP, Salesforce Einstein, Google Gemini, Microsoft Copilot.CSO Online article body
- Zenity reports OpenAI added a URL safety check before image rendering, and that it found a bypass via trusted cloud storage domains.Zenity ChatGPT Connectors post, mitigation section
Findings that cite this record
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
Jul 8, 2025
Aug 6, 2025
May 26, 2025
Jun 11, 2025
Jun 11, 2025
Jun 10, 2025