Sign in to baba News

The Desk, the news read to you every hour, is part of News Plus.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

↑↓ to move · ↵ to open · esc to close

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Security04:00 · Aug 6

Security Flaws in AI Browser Agents Expose Users to Remote Takeover Attacks

By רפאל קאהאן
Translated & summarized from Ynet by baba
The story · English

A new cybersecurity study by Israeli firm Zenity Labs, revealed at the Black Hat USA 2026 conference in Las Vegas, exposes critical vulnerabilities in autonomous AI agents integrated into popular web browsers. These flaws, dubbed PleaseFix, enable zero-click attacks that allow hackers to fully control AI agents in browsers such as Anthropic's Claude on Chrome, Perplexity's Comet, Google's Gemini on Chrome, OpenAI's Atlas ChatGPT, and Microsoft's Copilot on Edge.

The vulnerabilities stem from AI agents disregarding the long-standing Same-Origin Policy (SOP) that prevents websites from accessing data across different domains. AI agents designed to perform complex tasks across multiple sites blur these boundaries, enabling attackers to exploit a technique called Intent Collision. Malicious content embedded in social media posts, comments, or emails can confuse the AI agent, causing it to grant attackers full user permissions without any user interaction.

Zenity Labs demonstrated severe attack scenarios: in Anthropic's Claude, a single malicious email could expose Gmail data, Google Drive files, and Slack and X accounts, even with enhanced security modes enabled. Perplexity's Comet allowed attackers to access local files and lock users out of password managers, while OpenAI's Atlas enabled phishing via WhatsApp and unauthorized Amazon purchases using Amazon's AI assistant. Moreover, AI agents in Comet, Gemini, and Edge bypassed security to reach the local machine environment, executing reverse shells and database corruption to gain full device control.

The researchers also uncovered a HistoryFixing technique that implants fake browsing records, poisoning AI decision-making and causing destructive actions like deleting active AWS cloud servers and leaking private browsing histories. Zenity Labs co-founder and CTO Michael Bergory explained that integrating AI agents into browsers inherently conflicts with traditional security models, as AI agents can be tricked into performing unauthorized actions across sites.

The report highlights a recurring pattern where prioritizing user convenience over robust security leads to critical vulnerabilities, reminiscent of past issues like Microsoft's ActiveX and Cross-Site Scripting (XSS). The AI era introduces a new failure mode called Over-Agency, where autonomous AI decision-making opens doors to social engineering attacks directly targeting the AI model.

Zenity Labs responsibly disclosed these findings to major tech companies including Google, Microsoft, OpenAI, Anthropic, and Perplexity. While some promptly issued security patches, others defended the behaviors as intentional design features. This mixed response underscores the lack of industry standards and the precarious balance between AI assistant functionality and security in the race to develop the next-generation AI browser.

Read the original at Ynet

Ask About This Article

Duki reads it, and every newsroom on the same story, then answers with sources.

Open the live terminal