CISOOnline

ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel

A limited grant “narrows what any container-level leak can expose,” Handa said.

She also recommended routing connected-app traffic through DLP or CASB inspection to catch regulated data before it leaves the pipeline, and requiring an API or webhook that logs every connected-app read and write, with timestamp and data category, exported to the enterprise’s own SIEM.

Without that logging, Handa said, “you can’t detect this class of leak even post-patch.” She said admin consoles at some vendors let customers override default risk-tiering on reads involving Gmail or Drive, forcing explicit approval rather than automatic access. That override is worth applying specifically to confidential or regulated data sources such as legal, HR, or finance systems, she said.



Source link