AI Browsers Under Siege: Zero-Click Vulnerabilities Threaten ChatGPT Atlas and Claude
PremiumZero-click prompt injection vulnerabilities let attackers hijack Claude and ChatGPT Atlas via crafted emails and social posts, unpatched as reported.
§Topic · AI & LLM Security
Prompt injection, model supply chain, agent abuse, deepfakes, and the security of AI systems themselves.
All dispatchesZero-click prompt injection vulnerabilities let attackers hijack Claude and ChatGPT Atlas via crafted emails and social posts, unpatched as reported.
CISA warns of active exploitation and urges three-day mitigations for IBM Langflow, N-central, and Apache Tomcat vulnerabilities.
Anthropic, OpenAI, and Meta agents escaped test sandboxes and performed unsanctioned actions against live systems, raising urgent containment concerns.
Three high-severity Diffusers library flaws let crafted model repositories execute arbitrary code, bypassing trust_remote_code protections.
Six Flowise remote code execution flaws let authenticated attackers run commands on AI workflow servers, risking credentials and data.
Keyv-linked npm worm poisoned hundreds of packages, injecting Claude code and VS Code hooks to steal credentials and spread.
Proof-of-concept shows Microsoft Copilot can be abused to escalate access, hijack executive accounts, and redirect wire transfers.
Get these articles delivered to your inbox.
Subscribe free