Security vendor Radware disclosed “ZombieAgent,” a zero-click indirect prompt-injection vulnerability in OpenAI’s Deep Research agent that let an attacker implant hidden instructions causing the agent to autonomously exfiltrate sensitive data from within OpenAI’s own cloud infrastructure. Because the exfiltration happened entirely inside OpenAI’s servers rather than on a victim’s device or network, no corporate firewall, endpoint detection tool, or secure web gateway could see or block it, and the malicious instructions could persist in the agent’s memory to keep leaking data across future sessions. Radware reported the flaw to OpenAI under responsible disclosure before publishing.