LIVE · cybersecurity feed
Live wire
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentials
ai

Product showcase: AI Paper Trail shows the privacy cost of talking to AI

Proton’s AI Paper Trail is a free tool designed to make the information accumulated across AI conversations easier to see. It analyzes exported ChatGPT or Claude conversation data and produces a personal privacy report showing what can be inferred from those conversations. Proton says the uploaded data is deleted after analysis and is not stored on Lumo’s servers. AI conversations can reveal a sur

zeroday.news ·

Proton has launched a new free tool called AI Paper Trail, designed to help users understand the privacy implications of their conversations with artificial intelligence assistants. The tool analyzes exported conversation data from platforms like ChatGPT or Claude to generate a personal privacy report, highlighting what personal information can be inferred from these interactions.

AI Paper Trail operates by analyzing the content of user prompts to identify various categories of personal data. According to Proton, the data uploaded for analysis is deleted immediately after the report is generated and is not stored on Lumo’s servers. The initiative aims to make the often abstract concept of AI privacy more tangible for users.

Over time, even seemingly innocuous individual questions posed to AI assistants can accumulate to reveal a significant amount of personal information. This can include details about a user's work, relationships, habits, interests, purchasing patterns, and travel plans. The tool demonstrates how a comprehensive profile can be constructed from a history of interactions.

When a user exports their conversation history, for example from ChatGPT, and uploads the resulting ZIP file to AI Paper Trail, the tool processes the most recent 200 prompts. It then produces a report that includes a privacy type, an AI Exposure Score, a summary of personal information revealed, and an estimated advertising value of that data.

One user's experience with the tool, analyzing their personal ChatGPT history, resulted in an AI Exposure Score of 58 out of 100, placing them in the "Leaving receipts" category. The report identified 47 distinct data points and estimated an advertising value of $185, along with five "red flags." The analysis highlighted exposure across categories such as location, interests, technology use, finances, and relationships, with location, interests, and technology showing the highest levels of inferred data.

The user noted that many prompts considered revealing were not individually perceived as sensitive. However, when combined with other conversations, they contributed to a much more detailed personal profile. While the inferences made by AI Paper Trail are not presented as definitive facts—for instance, researching a topic does not automatically mean it pertains directly to the user—the tool effectively illustrates how seemingly unrelated pieces of information can quickly build up to form a comprehensive digital footprint.

The launch of AI Paper Trail underscores the growing awareness of data privacy in the context of AI interactions. It serves as a practical demonstration of how extensive personal details can be reconstructed from the cumulative trail of prompts left behind in conversations with AI assistants, prompting users to reconsider the privacy implications of their digital dialogues.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
aihigh

Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection

Researchers at Adversa AI have developed a novel attack called Cryptographic Context Injection, which bypasses AI safety filters by embedding malicious instructions within AES-encrypted payloads. This technique tricks AI models like xAI's Grok and Google's Gemini into decrypting and executing these hidden commands. In the case of Grok, the attack can lead to zero-click theft of user chat histories and personal data by disguising the malicious payload as a webpage summary request.

ransomware

Ransomware attackers are zeroing in on mid-market companies

Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite. The analysis covered 13,336 incidents with known revenue and defined mid-market companies as businesses with annual revenue between $10 million and $1 billion. Their share of incidents remaine

patch

Weekly Update 518: IoT Doorlock Nirvana with UniFi

I genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've worked out how to put it all into a residential house and have it make sense. There are a few basic tenets: Main power (never have to rely on

cloud

AWS makes it easier to spot firewall rules that have gone quiet

AWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them identify unused or redundant rules and validate whether security controls are working as intended. The capability covers stateful rules in both custom and managed rule groups, while stateless rules are not supported. The feature is enabled by defaul

malware

ToxicPanda Android malware uses VPN permissions to block Google Play

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]

iran

UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks

Hackers linked to Iran have successfully disabled a small UK power plant for four days, marking the first confirmed attack of its kind against the nation's energy infrastructure. The incident occurred concurrently with cyberattacks targeting water facilities across 12 US states. While the UK power plant's outage did not impact the national grid, the attack served as a demonstration of capability, with intentions likely focused on showcasing access rather than causing widespread disruption.