By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
MadisonyMadisony
Notification Show More
Font ResizerAa
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Reading: Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
Share
Font ResizerAa
MadisonyMadisony
Search
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Have an existing account? Sign In
Follow US
2025 © Madisony.com. All Rights Reserved.
Technology

Three Critical Claude.ai Flaws Enable Silent Data Exfiltration

Madisony
Last updated: March 19, 2026 8:26 pm
Madisony
Share
Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
SHARE

Security researchers at Oasis have identified three high-risk vulnerabilities in Claude.ai that combine to create a full attack chain known as “Cloudy Day.” This chain allows attackers to deliver targeted exploits and extract sensitive user data without detection. One vulnerability has been patched, while fixes for the remaining two are in progress.

Contents
The Cloudy Day Attack ChainPrompt Injection and Data ExfiltrationOpen Redirects Amplify the ThreatResponse and Patches

The Cloudy Day Attack Chain

The attack begins with invisible prompt injection through URL parameters on Claude.ai. Users can start a new chat with a pre-filled prompt using the format claude.ai/new?q=…, and attackers exploit this by embedding HTML tags to insert hidden malicious prompts. These prompts activate when the user presses Enter.

Prompt Injection and Data Exfiltration

Although Claude’s code execution sandbox blocks outbound network connections to third-party servers, it permits access to api.anthropic.com. Attackers can embed their own API key in the prompt, instructing Claude to scan the victim’s past conversations for sensitive information, compile it into a file, and upload it to the attacker’s Anthropic account via the Files API.

“No integrations or external tools needed, just capabilities that ship out of the box,” the researchers noted.

Open Redirects Amplify the Threat

To lure victims, attackers leverage open redirects on claude.com. URLs formatted as claude.com/redirect/ forward users to any domain without validation. This flaw pairs dangerously with Google Ads, which only checks hostnames, enabling attackers to craft deceptive ads that lead to malicious links.

Response and Patches

Anthropic has addressed the prompt injection issue. The Oasis team confirmed that the company is developing patches for the data exfiltration and open redirect vulnerabilities.

Subscribe to Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
[mc4wp_form]
Share This Article
Email Copy Link Print
Previous Article HIVE Digital Applied sciences Ltd. (HIVE) Companions with AMC Robotics to Advance AI Robotics HIVE Digital Applied sciences Ltd. (HIVE) Companions with AMC Robotics to Advance AI Robotics
Next Article Meta's rogue AI agent handed each id test — 4 gaps in enterprise IAM clarify why Meta's rogue AI agent handed each id test — 4 gaps in enterprise IAM clarify why

POPULAR

Iran Struggle Places International Vitality Markets on the Brink of a Worst-Case Situation
Technology

Iran Struggle Places International Vitality Markets on the Brink of a Worst-Case Situation

Asia is listening to PREP, and PREP is listening again
Investigative Reports

Asia is listening to PREP, and PREP is listening again

Excessive oil costs knock down shares and erase Wall Avenue’s hopes for a minimize to rates of interest
Money

Excessive oil costs knock down shares and erase Wall Avenue’s hopes for a minimize to rates of interest

Rescued Lab Rabbits Really feel Grass And Sunshine For The First Time
Pets & Animals

Rescued Lab Rabbits Really feel Grass And Sunshine For The First Time

4 Takeaways From Spherical 1 of the NCAA Males’s Basketball Match
Sports

4 Takeaways From Spherical 1 of the NCAA Males’s Basketball Match

My daughter is dishonest on her boyfriend together with her boss
National & World

My daughter is dishonest on her boyfriend together with her boss

David Raya Nearly Joined Bayern Munich Before Arsenal Move
Sports

David Raya Nearly Joined Bayern Munich Before Arsenal Move

You Might Also Like

File Low Snow within the West Will Imply Much less Water, Extra Hearth, and Political Chaos
Technology

File Low Snow within the West Will Imply Much less Water, Extra Hearth, and Political Chaos

States throughout the Western US are going through report low snowpack ranges in the midst of the winter season. The…

5 Min Read
Our Favourite Wi-Fi Router Is  Off
Technology

Our Favourite Wi-Fi Router Is $20 Off

Are you continuously resetting your dated router, or feeling like your streaming is not as snappy because it was? You…

3 Min Read
Cozy Earth Is Providing 40 % off Pajamas Proper Now
Technology

Cozy Earth Is Providing 40 % off Pajamas Proper Now

I like having a whimsical, comfy wardrobe, and that doesn’t apply simply to daytime garments. My pajama assortment is sort…

1 Min Read
They Helped Plan the January 6 Rally. Now Their Occasions Firm Is Raking in Tens of millions in Authorities Contracts
Technology

They Helped Plan the January 6 Rally. Now Their Occasions Firm Is Raking in Tens of millions in Authorities Contracts

An occasions firm whose associates helped stage the January 6, 2021 rally has signed contracts value over $26 million with…

6 Min Read
Madisony

We cover the stories that shape the world, from breaking global headlines to the insights behind them. Our mission is simple: deliver news you can rely on, fast and fact-checked.

Recent News

Iran Struggle Places International Vitality Markets on the Brink of a Worst-Case Situation
Iran Struggle Places International Vitality Markets on the Brink of a Worst-Case Situation
March 21, 2026
Asia is listening to PREP, and PREP is listening again
Asia is listening to PREP, and PREP is listening again
March 21, 2026
Excessive oil costs knock down shares and erase Wall Avenue’s hopes for a minimize to rates of interest
Excessive oil costs knock down shares and erase Wall Avenue’s hopes for a minimize to rates of interest
March 21, 2026

Trending News

Iran Struggle Places International Vitality Markets on the Brink of a Worst-Case Situation
Asia is listening to PREP, and PREP is listening again
Excessive oil costs knock down shares and erase Wall Avenue’s hopes for a minimize to rates of interest
Rescued Lab Rabbits Really feel Grass And Sunshine For The First Time
4 Takeaways From Spherical 1 of the NCAA Males’s Basketball Match
  • About Us
  • Privacy Policy
  • Terms Of Service
Reading: Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
Share

2025 © Madisony.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?