By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
MadisonyMadisony
Notification Show More
Font ResizerAa
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Reading: Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
Share
Font ResizerAa
MadisonyMadisony
Search
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Have an existing account? Sign In
Follow US
2025 © Madisony.com. All Rights Reserved.
Technology

Three Critical Claude.ai Flaws Enable Silent Data Exfiltration

Madisony
Last updated: March 19, 2026 8:26 pm
Madisony
Share
Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
SHARE

Security researchers at Oasis have identified three high-risk vulnerabilities in Claude.ai that combine to create a full attack chain known as “Cloudy Day.” This chain allows attackers to deliver targeted exploits and extract sensitive user data without detection. One vulnerability has been patched, while fixes for the remaining two are in progress.

Contents
The Cloudy Day Attack ChainPrompt Injection and Data ExfiltrationOpen Redirects Amplify the ThreatResponse and Patches

The Cloudy Day Attack Chain

The attack begins with invisible prompt injection through URL parameters on Claude.ai. Users can start a new chat with a pre-filled prompt using the format claude.ai/new?q=…, and attackers exploit this by embedding HTML tags to insert hidden malicious prompts. These prompts activate when the user presses Enter.

Prompt Injection and Data Exfiltration

Although Claude’s code execution sandbox blocks outbound network connections to third-party servers, it permits access to api.anthropic.com. Attackers can embed their own API key in the prompt, instructing Claude to scan the victim’s past conversations for sensitive information, compile it into a file, and upload it to the attacker’s Anthropic account via the Files API.

“No integrations or external tools needed, just capabilities that ship out of the box,” the researchers noted.

Open Redirects Amplify the Threat

To lure victims, attackers leverage open redirects on claude.com. URLs formatted as claude.com/redirect/ forward users to any domain without validation. This flaw pairs dangerously with Google Ads, which only checks hostnames, enabling attackers to craft deceptive ads that lead to malicious links.

Response and Patches

Anthropic has addressed the prompt injection issue. The Oasis team confirmed that the company is developing patches for the data exfiltration and open redirect vulnerabilities.

Subscribe to Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
[mc4wp_form]
Share This Article
Email Copy Link Print
Previous Article HIVE Digital Applied sciences Ltd. (HIVE) Companions with AMC Robotics to Advance AI Robotics HIVE Digital Applied sciences Ltd. (HIVE) Companions with AMC Robotics to Advance AI Robotics
Next Article Meta's rogue AI agent handed each id test — 4 gaps in enterprise IAM clarify why Meta's rogue AI agent handed each id test — 4 gaps in enterprise IAM clarify why

POPULAR

Queen Camilla’s Scottish Attire Sparks Online Debate
Politics

Queen Camilla’s Scottish Attire Sparks Online Debate

British Woman Faces Execution in Dubai After Fatal Altercation
world

British Woman Faces Execution in Dubai After Fatal Altercation

Rayonier: Timber REIT Poised for Growth with 5% Yield
business

Rayonier: Timber REIT Poised for Growth with 5% Yield

UK vs. Canada: Why Leaders Fall Faster in Britain
Politics

UK vs. Canada: Why Leaders Fall Faster in Britain

Jim Chalmers Addresses ‘Widow Tax’ Concerns Amidst Legislative Uncertainty
top

Jim Chalmers Addresses ‘Widow Tax’ Concerns Amidst Legislative Uncertainty

Crooks Season 2: Netflix Crime Drama Returns to Thrill Viewers
Entertainment

Crooks Season 2: Netflix Crime Drama Returns to Thrill Viewers

World Cup Knockout Stage: Your Most Anticipated Round of 32 Match
Sports

World Cup Knockout Stage: Your Most Anticipated Round of 32 Match

You Might Also Like

The Greatest Star Wars Presents for Everybody, From Padawans to Jedi Masters (2025)
Technology

The Greatest Star Wars Presents for Everybody, From Padawans to Jedi Masters (2025)

I've obtained many, many Star Wars items through the years. I spent the primary Christmas Day that I can bear…

2 Min Read
Anthropic cracks down on unauthorized Claude utilization by third-party harnesses and rivals
Technology

Anthropic cracks down on unauthorized Claude utilization by third-party harnesses and rivals

Anthropic has confirmed the implementation of strict new technical safeguards stopping third-party functions from spoofing its official coding consumer, Claude…

14 Min Read
Our Favourite Wi-fi Headphones for iPhone House owners Are 0 Off
Technology

Our Favourite Wi-fi Headphones for iPhone House owners Are $150 Off

Yesterday I wrote about a deal on the Nothing (1) Headset, an superior pair of energetic noise-canceling headphones that compete…

3 Min Read
3 ways AI is studying to know the bodily world
Technology

3 ways AI is studying to know the bodily world

Giant language fashions are working into limits in domains that require an understanding of the bodily world — from robotics…

9 Min Read
Madisony

We cover the stories that shape the world, from breaking global headlines to the insights behind them. Our mission is simple: deliver news you can rely on, fast and fact-checked.

Recent News

Queen Camilla’s Scottish Attire Sparks Online Debate
Queen Camilla’s Scottish Attire Sparks Online Debate
June 28, 2026
British Woman Faces Execution in Dubai After Fatal Altercation
British Woman Faces Execution in Dubai After Fatal Altercation
June 28, 2026
Rayonier: Timber REIT Poised for Growth with 5% Yield
Rayonier: Timber REIT Poised for Growth with 5% Yield
June 28, 2026

Trending News

Queen Camilla’s Scottish Attire Sparks Online Debate
British Woman Faces Execution in Dubai After Fatal Altercation
Rayonier: Timber REIT Poised for Growth with 5% Yield
UK vs. Canada: Why Leaders Fall Faster in Britain
Jim Chalmers Addresses ‘Widow Tax’ Concerns Amidst Legislative Uncertainty
  • About Us
  • Privacy Policy
  • Terms Of Service
Reading: Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
Share

2025 © Madisony.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?