Techtimes Vulnerability in AI Research Tools Allows Manipulation via Reddit Comments
Article Content
- •A single Reddit comment can manipulate AI research tools like ChatGPT and Gemini.
- •The vulnerability affects 54 to 71 percent of user-generated content retrieved by these systems.
- •The attack method, WARP, requires only the ability to post on public forums.
A critical vulnerability has been identified in AI deep research systems, including OpenAI's ChatGPT Deep Research and Google's Gemini Deep Research. Researchers from Cornell Tech revealed that a single Reddit comment can manipulate the recommendations of these systems, affecting 54 to 71 percent of user-generated content. The attack, termed WARP (Web Agent Retrieval Poisoning), requires no access to the systems or specific user queries. Instead, attackers can exploit the systems by posting misleading content on public forums. This vulnerability allows for the potential spread of scams and misinformation to thousands of users. The research paper detailing these findings was published in May 2026, with further analysis released on June 22, 2026. The attack method is particularly concerning due to the reliance of these AI systems on community-generated content for their outputs.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Google in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…