Saturday, 8 Aug 2026
Subscribe to AIWatcher
AIWatcher
  • Home
  • News

    Agent browsers get a lightweight rival as Cloudflare ships Kitesurf

    By
    AIWadmin

    Astra tests OpenAI’s own red line for cyber capability

    By
    AIWadmin

    AI conjures sixteen new viruses that kill resistant bacteria

    By
    AIWadmin

    Kimi K3 joins rogue agents after strolling out of its sandbox

    By
    AIWadmin

    Toronto startup Taalas joins AMD to hard-code models in chips

    By
    AIWadmin

    SK hynix commits $39B to two new fabs for the AI memory boom

    By
    AIWadmin
  • Articles

    Liquid AI’s tiny 2.6B model brings agents to phones and robots

    By
    AIWadmin

    Google Maps’ Ask assistant starts booking hotels and meals

    By
    AIWadmin

    Ex-Anthropic founders land $100M Google Cloud pact for Mirendil

    By
    AIWadmin

    Anthropic eases Fable 5’s biology blocks after researcher backlash

    By
    AIWadmin

    Tencent’s 295B-parameter Hy3 heads overseas with Apache 2.0 weights

    By
    AIWadmin

    Black Hat research turns agentic browsers into WhatsApp spam worms

    By
    AIWadmin
  • Spotlight

    Anthropic routes Claude Enterprise prompts through customer security servers

    By
    AIWadmin

    Suno watermarks AI songs and tightens downloads to curb misuse

    By
    AIWadmin

    Nine months of AI abuse ads slipped through Meta’s ad review

    By
    AIWadmin

    DeepMind’s cyclone model beats forecasters by a day, then goes open

    By
    AIWadmin

    Unitree’s Shanghai listing brings DeepSeek aboard with $21M

    By
    AIWadmin

    Meta’s new Muse Code agent plans, codes, and checks its own work

    By
    AIWadmin
  • Events
  • More
    • About
    • Services
    • Contact
  • 🔥
  • Alignment
  • Classification
  • Distillation
  • Explainability
  • Hallucination
  • Legal/Compliance
  • Medical
  • NLM
  • Mobility
  • Research
  • Robotics
  • Safety
  • Startups
  • Prompt
  • Python
  • RAG
  • RLHF
  • Token
  • Vision
Font ResizerAa
AIWatcherAIWatcher
  • Home
  • News
  • Articles
  • Spotlight
  • Events
  • About
Search
  • Quick Links
    • Home
    • News
    • Articles
    • Spotlight
    • Events
  • About AIWatcher
    • Mission
    • Services
    • Contact
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
News

Black Hat research turns agentic browsers into WhatsApp spam worms

Zenity found about 20 flaws across AI browsers, including an Atlas trick that spams contacts.

AIWadmin
Last updated: August 6, 2026 8:50 pm
AIWadmin
ByAIWadmin
Global AI news & information.
Follow:
Share
SHARE

A browser agent that fires off a mass message to every WhatsApp contact is one of roughly 20 attack scenarios Zenity researchers demonstrated at Black Hat this week. The flaws span AI browsers and extensions from OpenAI, Google, Anthropic, Microsoft, and Perplexity, and open paths to local files, password managers, and full browsing history.

OpenAI’s Atlas browser carried the most protections of those tested but was still bypassed. In one proof of concept, a fake newsletter signup page with instructions written in Hebrew steered Atlas to a signed-in WhatsApp web account and sent every contact the same message, a technique the researchers call a worm. The attack does not exploit a WhatsApp vulnerability.

In another demonstration, Atlas dropped a shipping address and a tablet into a logged-in Amazon account, then turned to the retailer’s Rufus assistant to finish the checkout. The researchers say Rufus was not hijacked, just asked by what it took to be the customer, and it complied. They call the pattern intent collision, where the AI merges legitimate user instructions with malicious web content.

OpenAI says it deployed an update addressing the issue in January and that protections extend to the new ChatGPT app. Atlas is being deprecated on August 9. Zenity argues for deterministic security barriers instead of AI judgment, which it says can nearly always be fooled.

TAGGED:agent securityAI securityAtlas browserBlack HatOpenAIprompt injectionvulnerability research
SOURCES:Wired
Share This Article
Email Copy Link Print
ByAIWadmin
Follow:
Global AI news & information.
Previous Article Anthropic routes Claude Enterprise prompts through customer security servers
Next Article Tencent’s 295B-parameter Hy3 heads overseas with Apache 2.0 weights
Ad imageAd image

You Might Also Like

EventsNews

AI Labs Sell Out: Anthropic and OpenAI Peddle Enterprise Access to the Highest Bidder

By
AIWadmin
News

Anthropic Launches Claude Science: An Integrated AI Workbench for Researchers

By
AIWadmin
News

AMD launches Helios rack system as credible Nvidia rival

By
AIWadmin
News

The Pentagon Says Anthropic Is a Security Risk. The NSA Is Using Its Hacker AI Anyway.

By
AIWadmin
AIWatcher
Facebook Twitter Youtube Linkedin Rss

Global AI News and Information
AIWatcher is your definitive source for AI updates worldwide, from Silicon Valley to Shanghai.
Our industry coverage keeps you in the loop with the latest news and trends shaping the future of AI.

Quick Links
  • News
  • Articles
  • Spotlight
  • Events
About Us
  • Mission
  • Services
  • Contact
  • Privacy Policy
  • Legal
© 2026 AIWatcher. All Rights Reserved.