By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
MadisonyMadisony
Notification Show More
Font ResizerAa
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Reading: Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
Share
Font ResizerAa
MadisonyMadisony
Search
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Have an existing account? Sign In
Follow US
2025 © Madisony.com. All Rights Reserved.
Technology

Three Critical Claude.ai Flaws Enable Silent Data Exfiltration

Madisony
Last updated: March 19, 2026 8:26 pm
Madisony
Share
Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
SHARE

Security researchers at Oasis have identified three high-risk vulnerabilities in Claude.ai that combine to create a full attack chain known as “Cloudy Day.” This chain allows attackers to deliver targeted exploits and extract sensitive user data without detection. One vulnerability has been patched, while fixes for the remaining two are in progress.

Contents
The Cloudy Day Attack ChainPrompt Injection and Data ExfiltrationOpen Redirects Amplify the ThreatResponse and Patches

The Cloudy Day Attack Chain

The attack begins with invisible prompt injection through URL parameters on Claude.ai. Users can start a new chat with a pre-filled prompt using the format claude.ai/new?q=…, and attackers exploit this by embedding HTML tags to insert hidden malicious prompts. These prompts activate when the user presses Enter.

Prompt Injection and Data Exfiltration

Although Claude’s code execution sandbox blocks outbound network connections to third-party servers, it permits access to api.anthropic.com. Attackers can embed their own API key in the prompt, instructing Claude to scan the victim’s past conversations for sensitive information, compile it into a file, and upload it to the attacker’s Anthropic account via the Files API.

“No integrations or external tools needed, just capabilities that ship out of the box,” the researchers noted.

Open Redirects Amplify the Threat

To lure victims, attackers leverage open redirects on claude.com. URLs formatted as claude.com/redirect/ forward users to any domain without validation. This flaw pairs dangerously with Google Ads, which only checks hostnames, enabling attackers to craft deceptive ads that lead to malicious links.

Response and Patches

Anthropic has addressed the prompt injection issue. The Oasis team confirmed that the company is developing patches for the data exfiltration and open redirect vulnerabilities.

Subscribe to Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
[mc4wp_form]
Share This Article
Email Copy Link Print
Previous Article HIVE Digital Applied sciences Ltd. (HIVE) Companions with AMC Robotics to Advance AI Robotics HIVE Digital Applied sciences Ltd. (HIVE) Companions with AMC Robotics to Advance AI Robotics
Next Article Meta's rogue AI agent handed each id test — 4 gaps in enterprise IAM clarify why Meta's rogue AI agent handed each id test — 4 gaps in enterprise IAM clarify why

POPULAR

Icahn Enterprises Q1 2026 Earnings: 9M Loss, alt=
business

Icahn Enterprises Q1 2026 Earnings: $459M Loss, $0.50 Dividend

Iranian Doctor Claims Green Card Denial is Retaliation After Lawsuit
top

Iranian Doctor Claims Green Card Denial is Retaliation After Lawsuit

Kate Garraway Supports Liam Halligan’s 300km Charity Bike Ride
Entertainment

Kate Garraway Supports Liam Halligan’s 300km Charity Bike Ride

David Walliams Seeks Romance on Raya Amid Isolation and Setbacks
top

David Walliams Seeks Romance on Raya Amid Isolation and Setbacks

TG Jones Faces Administration Risk Without 150 Store Closures
top

TG Jones Faces Administration Risk Without 150 Store Closures

Hantavirus Cruise Ship Outbreak Hits 13 Countries, Claims 3 Lives
world

Hantavirus Cruise Ship Outbreak Hits 13 Countries, Claims 3 Lives

Ronald McDonald Sings National Anthem at Triple-A Game, Players Laugh
Sports

Ronald McDonald Sings National Anthem at Triple-A Game, Players Laugh

You Might Also Like

Jon M. Chu Says AI Couldn’t Have Made One of many Greatest Moments in ‘Depraved’
Technology

Jon M. Chu Says AI Couldn’t Have Made One of many Greatest Moments in ‘Depraved’

If there’s anybody who understands the significance of viral advertising and marketing, it’s Depraved: For Good director Jon M. Chu.At…

4 Min Read
OnePlus 15 Evaluation: A Cellphone With Two-Day Battery Life
Technology

OnePlus 15 Evaluation: A Cellphone With Two-Day Battery Life

On days with mild use, I've 70 % left by bedtime. Once I spent extra time on the telephone, utilizing…

3 Min Read
Robot Police to Patrol Streets by 2031, Expert Predicts
Technology

Robot Police to Patrol Streets by 2031, Expert Predicts

Robot Officers Set to Transform PolicingRobot police officers capable of detecting, pursuing, and apprehending suspects will patrol streets worldwide by…

3 Min Read
YouTube Thinks AI Is Its Subsequent Massive Bang
Technology

YouTube Thinks AI Is Its Subsequent Massive Bang

Google discovered early on that video can be a fantastic addition to its search enterprise, so in 2005 it launched…

6 Min Read
Madisony

We cover the stories that shape the world, from breaking global headlines to the insights behind them. Our mission is simple: deliver news you can rely on, fast and fact-checked.

Recent News

Icahn Enterprises Q1 2026 Earnings: 9M Loss, alt=
Icahn Enterprises Q1 2026 Earnings: $459M Loss, $0.50 Dividend
May 9, 2026
Iranian Doctor Claims Green Card Denial is Retaliation After Lawsuit
Iranian Doctor Claims Green Card Denial is Retaliation After Lawsuit
May 9, 2026
Kate Garraway Supports Liam Halligan’s 300km Charity Bike Ride
Kate Garraway Supports Liam Halligan’s 300km Charity Bike Ride
May 9, 2026

Trending News

Icahn Enterprises Q1 2026 Earnings: $459M Loss, $0.50 Dividend
Iranian Doctor Claims Green Card Denial is Retaliation After Lawsuit
Kate Garraway Supports Liam Halligan’s 300km Charity Bike Ride
David Walliams Seeks Romance on Raya Amid Isolation and Setbacks
TG Jones Faces Administration Risk Without 150 Store Closures
  • About Us
  • Privacy Policy
  • Terms Of Service
Reading: Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
Share

2025 © Madisony.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?