AI assistant share links across major platforms (ChatGPT, Claude, Grok, Gemini, DeepSeek, and others) create unauthenticated, permanent, crawlable HTTP endpoints that expose user conversations and artifacts to public indexing. While most vendors have added noindex directives, the article demonstrates that legacy domains, archive services like the Wayback Machine, and platforms like DeepSeek and Grok still retain or serve exposed content. The risk is amplified in corporate environments where shadow AI usage and over-permissioned access can result in sensitive organizational data being published to durable public surfaces.
Data Exposure
3 posts
When AI Assistant Share Links Become Public Exposure KlueセキュリティインシデントとRecorded Futureへの影響 Recorded Future disclosed a security incident stemming from unauthorized access to Klue, a third-party marketing vendor. The attacker compromised an integration layer between Klue and other sales/marketing SaaS platforms, leveraging compromised OAuth tokens to access a subset of Recorded Future's Salesforce business data including customer contact names and email addresses. The malicious activity began on June 12, 2026, and was contained the same morning. Recorded Future's core systems, Intelligence Graph, and customer platform data were not affected. The incident underscores risks associated with third-party SaaS integrations and OAuth token security.
The Klue Security Incident and Its Impact on Recorded Future Recorded Future disclosed a data exposure incident resulting from a breach at their third-party marketing vendor, Klue. Attackers compromised an OAuth token used for the integration between Klue and Salesforce, granting unauthorized access to Recorded Future's Salesforce environment and exposing business data fields such as client contact details and contract information.