Skip to main content
See every side of every news story
Published loading...Updated

Microsoft finds security flaw in AI chatbots that could expose conversation topics

Microsoft researchers found Whisper Leak can identify sensitive AI chatbot topics with over 98% accuracy by analyzing encrypted traffic metadata without decrypting messages.

  • On November 10, Microsoft revealed Whisper Leak, a vulnerability that exposes topics in encrypted AI chat services affecting nearly all tested models, Microsoft researchers said.
  • Although TLS encrypts messages, Microsoft researchers found it leaves metadata about how messages travel visible, enabling the exploit without breaking TLS itself.
  • Testing on 28 LLMs showed researchers trained classifiers on recorded network rhythms, achieving over 98% accuracy and 100% detection at 1 in 10,000 sensitive conversations.
  • Following the disclosure, OpenAI, Mistral and xAI deployed mitigations while Microsoft advised users to avoid public Wi‑Fi, use a VPN, or choose non‑streaming models; our findings highlight the need to address metadata leakage.
  • Former military and security officials warn prompt injection and spoofing could let adversaries steal files or spread falsehoods, while traditional defenses miss side‑channel leaks like in the 2024 incident exposing over 300,000 files.
Insights by Ground AI

12 Articles

Defense NewsDefense News
+2 Reposted by 2 other sources
Center

Military experts warn security hole in most AI chatbots can sow chaos

Current and former military officers are warning that countries are likely to exploit a security hole in artificial intelligence chatbots.

·United States
Read Full Article

Artificial intelligence assistants, the engine force behind the cyber security revolution, have created an entry point for hackers stealing, closing or modifying user data, alerting cybernetic security specialists. IA assistants are computer programs that use exchangeable robots, or chatbots, to perform tasks that humans do online, such as buying an air pass or adding events to a calendar.

·Brazil
Read Full Article

AI assistants, protagonists of the revolution in this sector, have created a gateway to hackers to steal, delete or modify user data, warn cyber security experts. AI assistants are computer programs that use conversational robots, chatbots, to perform tasks that humans do online, such as buying a plane ticket or adding events to a calendar.You may be interestedTechnologyArtificial intelligence market in Mexico will reach a value of 32.884 millio…

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

CSO Online broke the news in on Monday, November 10, 2025.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal