Thursday, 24 Sep 2026
Subscribe to AIWatcher
AIWatcher
  • Home
  • News

    OpenAI slots two cheaper GPT-6 models beneath Astra

    By
    AIWadmin

    Researcher hijacks Meta’s Muse agent through a hidden setting

    By
    AIWadmin

    ChatGPT learns to take voice orders for office chores

    By
    AIWadmin

    YouTube hands creators an AI agent for titles and thumbnails

    By
    AIWadmin

    Listeners can now rewrite the Spotify algorithm in plain words

    By
    AIWadmin

    Anthropic’s Claude agents flag a new enzyme family in viral DNA

    By
    AIWadmin
  • Articles

    Data shop Snorkel AI banks $350M as labs stockpile training sets

    By
    AIWadmin

    Ema banks $77M to push AI employees into the back office

    By
    AIWadmin

    US military command randomises routes to outfox enemy models

    By
    AIWadmin

    Kyutai teaches a speech model to do arithmetic out loud

    By
    AIWadmin

    Nokia hands developers a no-training route to calibrated answers

    By
    AIWadmin

    An open model sorts eight overlapping speakers in real time

    By
    AIWadmin
  • Spotlight

    DeepMind keeps cloud memory encrypted behind device-held keys

    By
    AIWadmin

    Anthropic trims Opus costs and speeds output in a mid-cycle refresh

    By
    AIWadmin

    Cisco Talos builds a fingerprint library for AI-driven malware

    By
    AIWadmin

    Google parks idle agents in a new open source runtime

    By
    AIWadmin

    OpenAI gives mathematicians a voice but hands them no brake

    By
    AIWadmin

    NVIDIA teaches its robotics stack to take instructions from agents

    By
    AIWadmin
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Hats
      • T-Shirts
    • Cart
  • 🔥
  • Alignment
  • Classification
  • Distillation
  • Explainability
  • Hallucination
  • Legal/Compliance
  • Medical
  • NLM
  • Mobility
  • Research
  • Robotics
  • Safety
  • Startups
  • Prompt
  • Python
  • RAG
  • RLHF
  • Token
  • Vision
Font ResizerAa
AIWatcherAIWatcher
  • Home
  • News
  • Articles
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News
  • Articles
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
News

Black Hat research turns agentic browsers into WhatsApp spam worms

Zenity found about 20 flaws across AI browsers, including an Atlas trick that spams contacts.

AIWadmin
Last updated: August 6, 2026 8:50 pm
AIWadmin
ByAIWadmin
Global AI news & information.
Follow:
Share
SHARE

A browser agent that fires off a mass message to every WhatsApp contact is one of roughly 20 attack scenarios Zenity researchers demonstrated at Black Hat this week. The flaws span AI browsers and extensions from OpenAI, Google, Anthropic, Microsoft, and Perplexity, and open paths to local files, password managers, and full browsing history.

OpenAI’s Atlas browser carried the most protections of those tested but was still bypassed. In one proof of concept, a fake newsletter signup page with instructions written in Hebrew steered Atlas to a signed-in WhatsApp web account and sent every contact the same message, a technique the researchers call a worm. The attack does not exploit a WhatsApp vulnerability.

In another demonstration, Atlas dropped a shipping address and a tablet into a logged-in Amazon account, then turned to the retailer’s Rufus assistant to finish the checkout. The researchers say Rufus was not hijacked, just asked by what it took to be the customer, and it complied. They call the pattern intent collision, where the AI merges legitimate user instructions with malicious web content.

OpenAI says it deployed an update addressing the issue in January and that protections extend to the new ChatGPT app. Atlas is being deprecated on August 9. Zenity argues for deterministic security barriers instead of AI judgment, which it says can nearly always be fooled.

TAGGED:agent securityAI securityAtlas browserBlack HatOpenAIprompt injectionvulnerability research
SOURCES:Wired
Share This Article
Email Copy Link Print
ByAIWadmin
Follow:
Global AI news & information.
Previous Article Anthropic routes Claude Enterprise prompts through customer security servers
Next Article Tencent’s 295B-parameter Hy3 heads overseas with Apache 2.0 weights

You Might Also Like

News

OpenAI models run inside India on AWS Bedrock now

By
AIWadmin
News

Apple sues OpenAI over trade secret theft in AI hardware development

By
AIWadmin
News

Fears Mount as UK Deploys Humphrey AI Tool Tied to Big Tech

By
Zoe Chang
News

SEC probes banks behind Aschenbrenner’s AI hedge fund

By
AIWadmin
AIWatcher
Facebook Twitter Youtube Linkedin Rss

Global AI News and Information
AIWatcher is your definitive source for AI updates worldwide, from Silicon Valley to Shanghai.
Our industry coverage keeps you in the loop with the latest news and trends shaping the future of AI.

Quick Links
  • News
  • Articles
  • Spotlight
  • Events
About Us
  • Mission
  • Services
  • Contact
  • Privacy Policy
  • Legal
© 2026 AIWatcher. All Rights Reserved.