Three high-risk AI vulnerabilities discovered in Claude.ai: End-to-end attack chain exfiltrates sensitive information without user knowledge


  • Oasis researchers discover Claude’s “Cloudy Day” attack chain
  • Exploits include invisible prompt injection, data exfiltration via API, and open redirects
  • Anthropic fixed one vulnerability and fixes the other two in progress

Oasis security researchers recently discovered three vulnerabilities in Claude that, when used together, form a complete attack chain – from targeted delivery to victims to exfiltration of sensitive data.

The researchers dubbed it Cloudy Day and responsibly disclosed it to Anthropic.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top