Severity

critical

Exposure

5/5

Date of incident

February 20, 2026
ChatGPT DNS Exfill

reported

Tier -

A

ChatGPT runtime leaked via DNS — sandbox egress assumption failed at agent hop.
What Happened

Researchers abused DNS resolution path from ChatGPT code-analysis container to encode and leak conversation content; model assumed runtime had no outbound path and did not trigger user mediation.

Sumarry

Check Point Research disclosed ChatGPT data exfiltration via DNS side-channel from the purportedly isolated Python execution runtime; OpenAI deployed full fix February 20, 2026.

Detect

Egress allow-list on agent runtime; DNS anomaly detect

What Happened

Agent boundary deny on covert channels post-tool execution

Blekline //

Lineage block + egress policy on agent tool runtime

Without agent boundary //

Trust vendor sandbox marketing — no customer-controlled egress gate

Financial services AI security use case

Looking to integrate AI company-wide?