Researchers at Radware developed a prompt-injection technique called ZombieAgent that bypassed OpenAI’s URL restrictions and allowed data to be exfiltrated from ChatGPT one character at a time. OpenAI had previously restricted ChatGPT to open only URLs provided exactly as given and to refuse adding parameters, a change that blocked