Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Windows Tipps & SecurityNighthawk M7 Pro im Test: Flexibler, aber teurer 5G-Router(21.09.2026 um 10:30 Uhr)
Sichere ProgrammierungNeue Gmail-Funktion: So sparst du jetzt Zeit bei Einmalcodes(21.09.2026 um 10:00 Uhr)
Sichere ProgrammierungYour GIF exporter is fine — the container is the problem(21.09.2026 um 10:01 Uhr)
Sichere ProgrammierungCSS, Motion, or GSAP? I Choose by Who Owns the Animation(21.09.2026 um 10:12 Uhr)
Windows Tipps & SecurityNighthawk M7 Pro im Test: Flexibler, aber teurer 5G-Router(21.09.2026 um 10:30 Uhr)
Sichere ProgrammierungNeue Gmail-Funktion: So sparst du jetzt Zeit bei Einmalcodes(21.09.2026 um 10:00 Uhr)
Sichere ProgrammierungYour GIF exporter is fine — the container is the problem(21.09.2026 um 10:01 Uhr)
Sichere ProgrammierungCSS, Motion, or GSAP? I Choose by Who Owns the Animation(21.09.2026 um 10:12 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Your employees are pasting secrets into ChatGPT & Co-pilot & Claude & DeepSeek? Here's how to actually stop it.

Ask any engineering manager whether their team pastes code into ChatGPT and you'll get a nervous laugh. The honest answer is constantly — a stack trace here, a config file there, "just cleaning up this SQL." Most of it is harmless. Some of …

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

Ask any engineering manager whether their team pastes code into ChatGPT and you'll get

a nervous laugh. The honest answer is constantly — a stack trace here, a config file

there, "just cleaning up this SQL." Most of it is harmless. Some of it carries an AWS

key, a database password, or a customer's PII straight to a third-party model.



I've spent the last while looking at how teams try to control this, and most of the

common approaches quietly fail. Here's what doesn't work, what does, and why.






Why this isn't a normal DLP problem



Traditional DLP watches email, file shares, and cloud storage. An AI prompt leak skips

all of them: the data goes from a browser tab to an AI provider's API over HTTPS and

never touches the channels legacy DLP inspects.



It's also invisible after the fact. Once a prompt is sent there's no sent-mail copy, no

uploaded-file record. If you didn't catch it at the moment of submission, you have no

idea it happened. Prevention has to live in the browser, or it doesn't happen at all.






The approaches that don't hold up





  • Blocking AI tools outright. Employees just switch to their phone or a personal
    laptop. You lose the productivity and keep the risk.


  • Network proxies / CASBs. They can see the domain but struggle to inspect encrypted
    prompt content without heavy MITM infrastructure — and they don't understand a DOCX
    dropped into a chat window.


  • Policy + training. Sets expectations, stops nothing in the moment.


  • Post-hoc SaaS scanners. Find the exposure after the data already left. Good for
    audit, useless for prevention.






What actually works: intercept in the browser



The only place you can reliably read a prompt is where it's typed. A managed browser

extension can patch the page's network calls, read the prompt (and any attached files)

before they send, scan against your DLP rules, and block anything that matches — all

client-side, in well under a second, with no proxy and no rerouted traffic.



That's the model I've become convinced is right, and it's the approach

Slopfence takes — a browser-native AI security platform

that runs on ChatGPT, Claude, Gemini and Copilot, extracts text from uploaded Office/PDF

files, and blocks or redacts on the ten built-in policies plus your own rules.






A rollout that takes an afternoon




  1. Deploy the extension via Chrome/Edge GPO or your MDM (Jamf/Intune), pre-configured.

  2. Start with default policies (SSNs, cards, AWS keys, PII) active on install.

  3. Run alert-only for a week to baseline what your team is really sending.

  4. Flip high-severity rules to block; scope stricter rules to Finance, Legal, Eng.

  5. Review the audit trail and tune custom rules and document fingerprints.



If you want the deeper version of this playbook — the control matrix, the alert-vs-block

tradeoffs, and the rollout checklist — I wrote it up here:

how to stop secrets leaking to AI.






The uncomfortable truth is that your team has already adopted AI. The question is whether

you can see what they're sending it — and step in before the leak, not after.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Your employees are pasting secrets into ChatGPT & Co-pilot & Claude & DeepSeek? Here's how to actually stop it.

Thematisch verwandte Begriffe: Your, employees, pasting, secrets · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94030 | A security vulnerability has been detected in SerenityOS up to 3d83e4509…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick