OpenAI patched a vulnerability in its macOS ChatGPT application that could have enabled attackers to obtain sensitive data. Public reporting did not identify the flaw’s root cause, affected releases, patch version, CVE, disclosure source, or evidence of exploitation, but the issue highlights the client application as a sensitive attack surface for organizations deploying AI tools.
Separately, OpenAI said it banned accounts that used its models to support romance-scam operations, including victim outreach, translation, sustained engagement, and investment-fraud lures. The company described a three-stage process—“ping,” “zing,” and “sting”—and cited campaigns linked to Cambodia, U.S. medical professionals targeted through golf-related social-media engagement, and young men in Indonesia targeted through social-media advertisements.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
OpenAI published its case study, “Romance scams: AI-enabled romance scam workflows,” describing the ping, zing, and sting stages of such fraud and the importance of distribution channels. The company reported banning accounts used for scam outreach, translation, victim engagement, and investment-fraud lures.
The “Wrong Number” scam operation was exposed using cold-call SMS messages that promoted implausibly high returns for little work.
A pig-butchering operation frequently targeted American men in their 40s working in medical professions, engaging with their golf-related social-media posts. Operators used ChatGPT to generate more engaging messages that appeared less obviously non-native.
OpenAI patched a vulnerability in its macOS ChatGPT application that could have allowed attackers to access sensitive data. The supplied reporting does not identify affected versions, technical details, a CVE, or evidence of exploitation in the wild.
OpenAI identified its first published scam disruption as a newly established criminal operation in Cambodia that used ChatGPT to generate romance-scam messages, including messages distributed through social media.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.