Skip to main content

Share story

Security

OpenAI unveils Lockdown Mode to protect sensitive data from prompt injection attacks

OpenAI unveils Lockdown Mode to protect sensitive data from prompt injection attacks Image: Primary
OpenAI announced a new feature called Lockdown Mode. The feature provides additional protection from prompt injection attacks. In these attacks malicious chatbot instructions are hidden in web pages and other content sources. Lockdown Mode disables live web browsing so users can only access cached content. It disables the retrieval and display of images from the web although image generation remains available. Deep research and agent mode are also turned off. The company acknowledges that even with Lockdown Mode turned on ChatGPT could still be vulnerable to prompt injections. These could appear in cached web content or in an uploaded file. They could still affect the behavior or accuracy of a response. The goal is to reduce the likelihood that sensitive data gets shared in the process. OpenAI says Lockdown Mode is not intended for everyone. It is designed for people and organizations that handle sensitive data and want stricter protection from data exfiltration risks related to prompt injection. The company is currently rolling Lockdown Mode out to self-serve ChatGPT Business accounts as well as eligible personal accounts.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from TechCrunch, Reuters and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Infrastructure
Security Infrastructure

CISA adds two exploited Check Point flaws to federal fix list

The U.S. Cybersecurity and Infrastructure Security Agency added two Check Point Security Gateway flaws to its list of known exploited vulnerabilities and told federal agencies to apply fixes or mitigations by September 25. Check P...

Security Infrastructure
Security Infrastructure

Analysis identifies two flaws behind exploited MikroTik router takeover chain

CERT Polska has identified the two RouterOS SSH flaws behind a previously reported attack that can give intruders administrative control of exposed MikroTik routers without completing authentication. One flaw lets a connection rea...