NEWS
New NITDA Cybersecurity Warning: OpenAI GPT-4.0 & GPT-5 Vulnerabilities Expose Nigerians to Data Theft, Silent Attacks and Memory Poisoning
Nigeria’s National Information Technology Development Agency (NITDA) has issued a fresh and urgent cybersecurity advisory alerting the public to newly uncovered security flaws in OpenAI’s most advanced large language models.
According to the agency, the vulnerabilities discovered in GPT-4.0 and GPT-5 could expose millions of users to serious data-leakage risks without their knowledge or direct interaction.
The warning, released through NITDA’s Computer Emergency Readiness and Response Team (CERRT.NG) on Sunday via its official X account, reveals that seven critical weaknesses have been identified in the AI models. These flaws allow attackers to manipulate ChatGPT through indirect prompt injections hidden inside harmless-looking websites, links, or online comments.
The advisory explains that attackers can embed malicious instructions inside “webpages, comments, or crafted URLs,” triggering unwanted actions while users are browsing, summarising or searching with ChatGPT.
Shockingly, users may be attacked “without clicking anything,” as the models automatically analyse and process online text.
CERRT also confirmed that some of the vulnerabilities enable threat actors to bypass OpenAI’s safety filters, exploiting trusted domains or markdown rendering weaknesses to inject harmful commands.
One of the most alarming revelations is the possibility of long-term AI manipulation.
According to the agency, attackers could even “poison ChatGPT’s memory so that injected instructions persist across future interactions,” creating the risk of ongoing behavioural influence in both personal and enterprise systems. While OpenAI has attempted partial fixes, CERRT maintains that large AI models still cannot reliably distinguish legitimate requests from maliciously embedded instructions, making users vulnerable to covert attacks.
According to NITDA, the risks posed by the vulnerabilities include unauthorised system actions, manipulated or misleading outputs, silent information leakage, and long-term behavioural alteration due to memory poisoning. The agency further warned that these impacts could occur without direct user action, especially when ChatGPT processes search results or webpages containing concealed payloads.
Issuing the directive in Abuja, the agency’s Director of Corporate Affairs and External Relations, Mrs. Hadiza Umar, confirmed the security threat, emphasising the seven weaknesses and explaining how attackers embed hidden instructions in online platforms, misleading the system into executing harmful actions. She reiterated that, despite OpenAI’s adjustments, the root challenge remains unsolved: distinguishing genuine user intent from harmful embedded data.
She warned that the flaws carry “substantial risks, including unauthorised actions, information leakage, manipulated outputs and long-term behavioural influence due to memory poisoning.”
To mitigate the threat, the agency advised individuals and organisations to limit or disable ChatGPT’s browsing and summarisation features for untrusted websites, enable the AI’s capabilities such as browsing or memory only when absolutely necessary, and regularly update GPT-4.0 and GPT-5 systems to receive vulnerability patches that address known exposures.
In a related warning, NITDA through CERRT.NG also raised concerns about newly emerging security problems affecting Cisco Secure Firewall ASA and Cisco Secure Firewall Threat Defense (FTD) systems. Cybercriminals are said to be exploiting a fresh attack method capable of forcibly rebooting these devices, leading to unexpected network outages.
According to the advisory posted on NITDA’s official X page on Monday, attackers are combining older vulnerabilities to develop a new technique that can make firewalls “restart without warning,” resulting in denial-of-service incidents and widespread network instability across banks, government offices, internet service providers, corporate organisations, and critical infrastructure systems.
NITDA is strongly advising Nigerians, organisations, network administrators and enterprise users to apply immediate security controls, patch and update AI and firewall systems, restrict AI browsing within corporate environments, and closely monitor all systems for suspicious or abnormal activities as Nigeria increases its dependence on artificial intelligence and digital infrastructure.
