Posts

Showing posts with the label PromptInjection

ChatGPT’s Atlas Browser - Groundbreaking—but Are You Safe Using It?

Image
ChatGPT Atlas, the new AI-powered browser from OpenAI, is a big leap forward—but yes, it comes with real security risks. Among them: prompt-injection and UI/agent spoofing vulnerabilities that have already been demonstrated. If you avoided Atlas because you weren’t on a Mac or in the Apple ecosystem, you might have sidestepped that particular rollout , but it doesn’t mean you’re in the clear overall. These are systemic risks in “agentic” AI browsers. What Atlas Is—and Why It’s a Big Deal OpenAI launched ChatGPT Atlas: a browser built on Chromium with the ChatGPT assistant in the sidebar, able to act on websites (summarize, compare, plan, shop) rather than simply answer questions. It premiered on macOS; other platforms (Windows, iOS, Android) are “coming soon.” This matters because it changes the browser from “you browse, then ask ChatGPT” to “ChatGPT helps browse (or browses for you)”. That shift opens up new threats. The Security Gotchas (Plain English) 1) Prompt Injection / A...

One Click, Many Risks - Prompt Injection in Comet and Other AI-Powered Tools

Image
This information is also available on my  YouTube Channel  at:  https://youtu.be/1eGE8cTSwAY If you prefer, you can also listen to this information on  my  Podcast  at:  https://open.spotify.com/episode/7EXmsWfOK5eaVGLatIQGfx?si=cuEeU1PeQCypYJBk60elNw https://open.spotify.com/episode/2J23JX0aa0ci27OdN5B3CB?si=lOXtRMEoQ_i64hjxr_tJ7w   Security researchers have uncovered a new exploit dubbed CometJacking that turns a single malicious click into a silent data leak. While it was demonstrated on the Comet Browser’s built-in AI agent, the bigger story is that this type of attack could hit any AI-enabled browser or tool that mixes untrusted content with privileged access. How CometJacking Works: Comet is marketed as an “AI-native” browser. Instead of just displaying websites, it runs a built-in assistant that can read your email, calendar, documents, and other connected services to help you work. A malicious link can hide a prompt-injection payload that ...