Close Menu
    What's Hot

    How to Travel With a Car Seat

    How to boost brain health at work in the age of AI

    Times/Siena Poll Finds Talarico and Paxton Tied in Texas Senate Race

    Facebook X (Twitter) Instagram
    Trending
    • How to Travel With a Car Seat
    • How to boost brain health at work in the age of AI
    • Times/Siena Poll Finds Talarico and Paxton Tied in Texas Senate Race
    • Texas Is a Tossup. The Times/Siena Poll Points to How It Got There.
    • U.S. and Iran Gear Up for Meetings in Qatar: Live Updates
    • Crypto exchange OKX wants AI agents to hire and pay each other
    • How Grindr’s C.E.O. Adopted A.I.: ‘I Just Imposed It’
    • Leeds Rhinos quell Jake Connor concerns ahead of Magic Weekend clash with rivals Bradford Bulls | Rugby League News
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials

    adminBy adminJune 30, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJun 30, 2026Agent Security / Browser Security

    New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials

    Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants into copying a user’s credentials and sending them to an attacker.

    The targets included OpenAI’s ChatGPT Atlas, Perplexity’s Comet, and Anthropic’s Claude browser extension.

    An AI browser is one that can act for you, not just read pages. Switch it to agent mode, and it can click, type, and reach into the sites you are already signed into. That access is the whole point, and it is also the problem.

    Cybersecurity

    The trick works because of how these agents read. The web page and your own instructions arrive as a single stream of text. That lets a malicious page slip in commands dressed up as ordinary content or game rules, and the agent cannot reliably tell the difference. Researchers call this indirect prompt injection.

    How the trick works

    The attack starts with a web page built as a puzzle. To fit its dystopian theme, the puzzle rewards wrong answers, like insisting that 2 + 2 = 5. Once the agent accepts that “wrong” is the winning move, it follows game logic instead of safety logic. The final step of the puzzle asks it to grab the user’s credentials, and not one of the six agents flagged that as something it should refuse.

    The dangerous part is where the agent looks. In the test, a link was sent to the victim’s work GitHub repository, where it pulled SSH login credentials and passed them to the attacker.

    LayerX used a harmless plaintext file, but the same trick could point the agent at other resources it can reach in that session: open tabs, signed-in accounts, and internal tools. The agent did not hesitate. Afterward, it cheerfully reported the theft as a win.

    The name nods to BioShock, where a brainwashed character obeys the trigger phrase “Would you kindly?” The agent is no different. It trusts the context it is handed. Change the context, and you change what it will do.

    LayerX has shown this pattern before, demonstrating that a single click could hijack Perplexity’s Comet and quietly steal data.

    What the vendors did, and what to do

    By LayerX’s account, the responses were uneven. It reported the issue to vendors between October 2025 and January 2026. OpenAI fixed it in ChatGPT Atlas. Perplexity closed the report without acting on it.

    Fellou, Genspark, and Sigma did not respond. Anthropic tried to patch its Claude extension, but LayerX says the fix did not hold.

    To shut the attack down, LayerX wants AI browsers to ask before reading from logged-in accounts. One prompt, “I’m about to copy data from your GitHub repository. Continue?”, would break the chain.

    Cybersecurity

    It also wants agents to notice when a page tells them the normal rules no longer apply, and to let users set hard limits on what an agent can touch. Winning a game is no reason to open a private repository.

    For users, the advice is shorter. Treat agent mode with care: whatever you are signed in to is fair game, so decide what the browser should see and cut that access when you are done. For security teams, the same logic scales up.

    An AI browser in agent mode is effectively another account with reach into company systems, and it should get the narrowest access a task needs rather than a standing pass to everything the user can touch.

    The common thread across these findings is that handing an AI agent the keys to your signed-in accounts turns a jailbreak from a party trick into real access.

    attack BioShocking Browsers Credentials Leaking tricks user
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleThe Prom Went On in Kyiv, but Masha’s Date Danced Alone
    Next Article Leeds Rhinos quell Jake Connor concerns ahead of Magic Weekend clash with rivals Bradford Bulls | Rugby League News
    admin
    • Website

    Related Posts

    Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs

    June 30, 2026

    Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild

    June 30, 2026

    Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

    June 30, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    How to Travel With a Car Seat

    How to boost brain health at work in the age of AI

    Times/Siena Poll Finds Talarico and Paxton Tied in Texas Senate Race

    Texas Is a Tossup. The Times/Siena Poll Points to How It Got There.

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by