Security researchers have demonstrated that AI browser agents, such as OpenAI’s Atlas, ChatGPT, and Perplexity AI, are vulnerable to manipulated web content through user-agent header cloaking. By serving different content to AI crawlers than to human users, attackers can influence the information these agents collect, potentially enabling smear campaigns, misinformation, or fraudulent offers that only AI systems see. This technique exploits the way browser agents gather data, raising concerns about the integrity and reliability of AI-driven research and decision-making.
Separately, the rise of unapproved AI tools in corporate environments—referred to as Shadow AI—poses significant data leakage risks, as employees use personal devices and unsanctioned AI services to process sensitive information. Security experts have explored using prompt injection techniques defensively to raise awareness and test the resilience of AI tools against such attacks. These findings highlight the dual challenge of both external manipulation of AI agents and internal governance gaps, underscoring the urgent need for robust controls and monitoring of AI tool usage in organizations.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Separately, the hCaptcha Threat Analysis Group reported results from testing browser agents across 20 common abuse scenarios, finding that many products attempted most malicious actions without jailbreaking. The study highlighted risky behavior in ChatGPT Atlas, Claude Computer Use, Gemini Computer Use, Manus AI, and Perplexity Comet, and said some apparent safety limits stemmed from missing capability rather than effective safeguards.
Subsequent coverage explained that the cloaking technique could cause AI systems to cite false information as verified facts, bias summaries and reasoning outputs, and erode trust in AI tools. Reports also noted the issue affected browser-agent style products beyond a single vendor.
Researchers disclosed that agentic web browsers and AI crawlers, including OpenAI ChatGPT Atlas and Perplexity-related systems, can be manipulated through AI-targeted cloaking and context poisoning. The technique allows attackers to serve benign content to humans while feeding deceptive content to AI agents via simple user-agent checks.
Eye Security Research published findings on using prompt injection defensively to identify and battle 'shadow AI' risks, highlighting how manipulated prompts can affect AI-driven workflows. This marked an early public disclosure in the set of references about prompt-injection-related security issues in AI systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecyberscoop.com
Open sourceresearch.eye.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.