惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
G
Google Developers Blog
Blog — PlanetScale
Blog — PlanetScale
P
Proofpoint News Feed
博客园 - Franky
L
LangChain Blog
GbyAI
GbyAI
A
About on SuperTechFans
MongoDB | Blog
MongoDB | Blog
F
Fortinet All Blogs
Y
Y Combinator Blog
Stack Overflow Blog
Stack Overflow Blog
博客园 - 叶小钗
N
Netflix TechBlog - Medium
D
DataBreaches.Net
Martin Fowler
Martin Fowler
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Hugging Face - Blog
Hugging Face - Blog
博客园_首页
爱范儿
爱范儿
罗磊的独立博客
H
Help Net Security
云风的 BLOG
云风的 BLOG
C
Check Point Blog

Futurism

Zuckerberg's Pervert Glasses Have Been So Publicly Shamed That Meta's Reportedly Now Working on a Version With No Camera Meta Is Using Instagram Users' Photos to Build a Universal Facial Recognition System for Its Hated Smart Glasses, Class Action Lawsuit Claims Sam Altman Now Trying to Gain Control of Electric Grid Top Chinese Court Issues Sweeping Legal Crackdown on AI Deepfakes Meta Releases Uber-Creepy AI Chatbot as Its Platforms Crumble Under Grotesque Child Abuse LG TVs Caught Secretly Recording Users and Scanning Their Homes For Other Devices, Even When Disconnected From the Internet People Are Telling Their Darkest Thoughts to AI Without Realizing They Can Easily Become Public Hackers Are Selling Stolen Scans of 153 Million US and Canadian Drivers Licenses, Which Very Likely Include Yours FBI Now Allowing History of Bestiality Among New Recruits The Transcripts of OpenAI Models Plotting Together to Commit an Actual Crime Is Pretty Chilling Flock Is Quietly Selling Powerful Drones That Scan License Plates From the Sky McDonald's Has Hundreds of Pages of Intel on Its Repeat Customers, and You Can Get a Copy of Yours Man Wearing Pervert Glasses Films Himself Harassing Famous Female Comedian in the Middle of TV Shoot Sensing He's in Deep Trouble, Flock Safety CEO Says It's All Been a Big Misunderstanding Hackers Created a Device That Can Take Over a Boeing 737 Jet's Autopilot Without Anyone Noticing Man Covers Car in Special Wrap That Breaks Flock Cameras' Electronic Brains Scammers Tremble as AI Comes for Their Jobs Why Aren't Any AI Companies Watching Their Frontier Models to Make Sure They Don't Go on Hacking Sprees? Jealously Watching OpenAI and Anthropic, Meta Suddenly Claims That Its AI Went on a Hacking Spree Too OpenAI's Escaped Models Were Allegedly Rampaging More Extensively Than Previously Reported If You AI-Generate Code, Hackers Just Found a Devious Method to Install Malware Directly on Your Computer This New Meta "Advertisement" Is Absolutely Brutal Suspicion Grows About OpenAI's Tale About Its Rogue Hacker AI OpenAI Says a Group of Its Models Broke Out of Secure Containment and Hacked a Prominent AI Site It's Laughably Easy to Poison Open-Weight AI Models, Researcher Finds Meta’s AI Support Bot Is Giving Hackers Access to Other People’s Instagram Accounts Just by Asking Websites Are Spying on Your Solid State Drive The MyPillow Guy’s Entire Business is Being Held Hostage by Hackers Riot Games Denies Using Anti-Cheat Software That Bricks Hackers’ Computers The Trump Phone Appears to Have Already Leaked Its Customers’ Personal Information Through a Glaring Exploit
AI Browsers Can Basically Be Hypnotized Into Turning Agai...
Frank Landymore · 2026-07-03 · via Futurism

A color-treated photograph of a man's hands operating a keyboard in the dark.

Shutterstock / Futurism

Sign up to see the future, today

Can’t-miss innovations from the bleeding edge of science and tech

A new hack can trick AI browsers into breaking their guardrails by constructing a false reality around them where the rules are made up and actions don’t have consequences. Put another way, they’re basically hypnotized into doing stuff that could have devastating consequences for the user.

These were the findings of new research from the cybersecurity firm LayerX, and they further illustrate the dangers posed by weaving autonomous AI agents into the software we use to navigate the internet.

Through the hack, the researchers demonstrated that leading AI browsers like OpenAI’s ChatGPT Atlas, Perplexity AI’s Comet, and Anthropic’s Claude plugin for Google Chrome could be duped into executing any command, allowing a hacker to change a user’s password, install malware, and steal their information.

They call this hack “BioShocking,” a reference to the video game BioShock, in which the protagonist is hypnotized into doing stuff against their will with a specific phrase.

Normally, the “AI operates under the assumption that its context is real, and its behavior must therefore fall within the bounds of its safety guardrails,” the researchers wrote. But if the AI is tricked into thinking its context is a “fantasy,” then there’s nothing holding the AI back.

This works by having the AI engage in a sort of game. The researchers created a proof of concept page with a BioShock-themed puzzles in which the AI is rewarded for giving intentionally incorrect answers, like 2+2 = 5 (another allusion to the acclaimed 2007 title). 

This essentially taught the AI browsers that “incorrect” actions are acceptable, untethering them from reality to the extent that they espouse paradoxical statements. “Victory is defeat,” a brainwashed AI browser intones, in a reference to George Orwell’s novel “1984.”

What this looks like in practice: an unwitting user could open a seemingly innocuous web page laced with the malicious prompts — a tactic known as prompt injection — that trap the AI browser in the malicious game. In one scenario shared by the researchers, the AI is tricked into navigating to “/code,” which opens their employer’s code repository on GitHub.

“In a real attack scenario, that redirect could point anywhere in the user’s browser session — open tabs, authenticated repositories, internal tools,” the researchers noted.

The hack happens out in the open, so a user can easily intervene once they see their AI engaging in malicious words in the window — if they’re paying attention, that is. On the other hand, the vulnerability exposed is undeniable: the context that AI browsers act in can be manipulated by brainwashing it into thinking it’s playing a game. In this age, hackers no longer have to rely solely on tricking the user; now they can trick their gullible AI helpers instead.

More on AI: Top AI Researchers Terrified of a “Chernobyl Moment”: a Mass Casualty Event, or Worse, That Turns the World Against AI Forever