Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Box CEO Aaron Levie talks about how AI is changing the landscape of enterprise SaaS

San Francisco Mayor: “We should be a testing ground for emerging technologies”

Experts report a surge in automated botnet attacks targeting PHP servers and IoT devices

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » New cloaking attack targets AI to trick AI crawlers into citing misinformation as verified fact
Identity

New cloaking attack targets AI to trick AI crawlers into citing misinformation as verified fact

userBy userOctober 29, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

October 29, 2025Ravi LakshmananMachine learning/AI safety

Cybersecurity researchers have flagged a new security issue in agent web browsers such as OpenAI ChatGPT Atlas that exposes the underlying artificial intelligence (AI) model to context poisoning attacks.

The attack, devised by AI security firm SPLX, allows malicious attackers to set up websites that serve different content to browsers and AI crawlers run by ChatGPT and Perplexity. This technology is code-named cloaking for AI.

This approach is a type of search engine cloaking, which refers to the practice of displaying one version of a web page to users and displaying another version to search engine crawlers, with the ultimate goal of manipulating search rankings.

DFIR retainer service

The only difference in this case is that the attackers have optimized AI crawlers from different providers with simple user agent checks that lead to manipulation of content delivery.

“These systems rely on direct search, so any content they provide becomes the AI ​​overview, overview, or ground truth for autonomous inference,” said security researchers Ivan Vlahov and Bastien Eymery. “This means that with a single conditional rule, ‘If user agent = ChatGPT, serve this page instead,’ you can shape what millions of users will perceive as authoritative output.”

SPLX said that while seemingly simple, cloaking targeting AI can turn into a powerful weapon of disinformation and undermine trust in AI tools. Telling an AI crawler to load something else instead of the actual content can also introduce bias and affect the results of systems that rely on such signals.

“AI crawlers can be fooled just as easily as early search engines, but the downstream impact is much greater,” the company said. “As an SEO [search engine optimization] AIO integration is progressing [artificial intelligence optimization]it manipulates reality. ”

The hCaptcha Threat Analysis Group (hTAG) announced the disclosure after analysis of the browser agent against 20 of the most common exploit scenarios, from multi-account to card testing and support impersonation, found that the product attempted nearly all malicious requests without requiring a jailbreak.

Additionally, the study found that in scenarios where an action was “blocked,” most of the stops were due to a lack of technical functionality in the tool, rather than due to a safety device built into the tool. hTAG noted that ChatGPT Atlas was found to perform dangerous tasks when included as part of debugging exercises.

CIS build kit

Claude Computer Use and Gemini Computer Use, on the other hand, have been observed to be able to perform risky account operations such as password resets without any constraints, and the latter has also shown aggressive behavior when it comes to brute force couponing on e-commerce sites.

hTAG also tested Manus AI’s security measures and found that it successfully performed account takeover and session hijacking, while Perplexity Comet performed unprompted SQL injections to extract hidden data.

“Agents often went above and beyond, attempting SQL injection without a user’s request or attempting to bypass paywalls by injecting JavaScript onto pages,” the paper said. “Due to the almost complete lack of safeguards we observed, it is very likely that these same agents could be rapidly used by attackers against legitimate users who happened to download them.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDisrupt 2025: Day 3 | Tech Crunch
Next Article Experts report a surge in automated botnet attacks targeting PHP servers and IoT devices
user
  • Website

Related Posts

Experts report a surge in automated botnet attacks targeting PHP servers and IoT devices

October 29, 2025

Discover practical AI tactics for GRC — join our free expert webinar

October 29, 2025

Ghost identities, poisoned accounts, and AI agent chaos

October 29, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Box CEO Aaron Levie talks about how AI is changing the landscape of enterprise SaaS

San Francisco Mayor: “We should be a testing ground for emerging technologies”

Experts report a surge in automated botnet attacks targeting PHP servers and IoT devices

New cloaking attack targets AI to trick AI crawlers into citing misinformation as verified fact

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.