Sunday , August 2 2026
CISA

CISA chief at it again: uploads sensitive files into ChatGPT

The acting director of the Cybersecurity and Infrastructure Security Agency (CISA) uploaded sensitive contracting documents marked “for official use only” into the public version of ChatGPT last summer, triggering multiple automated security alerts designed to prevent data exfiltration from federal networks, four Department of Homeland Security (DHS) officials told Politico.

Madhu Gottumukkala, CISA’s interim head since May 2025, had secured special permission from the agency’s Chief Information Officer to use the AI tool shortly after joining.

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

At the time, ChatGPT remained blocked for other DHS staff. The uploads occurred in early August 2025, with cybersecurity sensors repeatedly flagging them with multiple warnings in the first week alone. None of the files were classified, but they contained sensitive contracting information not meant for public release.

CISA’s defenses detected the activity, prompting senior DHS officials to launch an internal review to evaluate potential harm to national security.

Gottumukkala discussed the uploads with DHS leaders, including then-acting general counsel Joseph Mazzara and Chief Information Officer Antoine McCord. He also met with CISA’s CIO Robert Costello and chief counsel Spencer Fisher in August to address the handling of “for official use only” (FOUO) material.

DHS policy mandates investigating such exposures, assessing causes, and considering actions from retraining to security clearance revocation. One anonymous official criticized Gottumukkala harshly: “He forced CISA’s hand into making them give him ChatGPT, and then he abused it.” The review’s outcome remains undisclosed.

Public ChatGPT shares user inputs with OpenAI, which boasts over 700 million active users. This risks sensitive data training models accessible to adversaries, including state-backed hackers from Russia and China, precisely the threats CISA counters.

CISA spokesperson Marci McCarthy stated Gottumukkala used ChatGPT “with DHS controls in place” under a “short-term and limited” exception, last accessing it in mid-July 2025. She emphasized the agency’s AI commitment per President Trump’s executive order.

In contrast, approved DHS tools, such as the internal DHSChat, store data on federal networks. All federal employees receive training on handling sensitive documents.

Gottumukkala’s tenure has drawn scrutiny. Six career staff members were placed on leave after his unsanctioned counterintelligence polygraph failure.

In testimony, he denied the “failed test” premise. Last week, he attempted to oust Costello, but was blocked by appointees, as reported by Politico.

Check Also

EY

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group …