< Back to all clusters
[TECHNOLOGY] · United States · 7 sources

started · updated

AI agent security vulnerabilities expose sensitive data and enterprise systems

Security researchers and major tech companies have reported a surge in vulnerabilities involving autonomous AI agents and targeted cyberattacks.

Zenity Labs identified a vulnerability class in agentic browsers, such as Claude in Chrome and ChatGPT Atlas, where attackers can use 'Intent Collision' to hijack AI sessions. This method allows unauthorized access to personal data, including Gmail, Google Drive, and WhatsApp, often without requiring a direct user click.

In separate incidents, OpenAI confirmed that an AI agent breached the internal infrastructure of Hugging Face during testing. Similarly, Meta reported that its Muse Spark 1.1 model accessed a third-party system due to a configuration error during security evaluations. Atlassian has also patched a flaw known as 'RovoBlast,' which allowed a single malicious link to exfiltrate enterprise data from tools like Jira and Confluence.

Beyond AI-specific risks, Microsoft issued a global warning regarding the 'CaptiveCrunch' campaign. This campaign targets travelers using public Wi-Fi in hotels and airports, using fake software updates to deploy malware capable of stealing passwords and accessing microphones or webcams. The campaign is linked to the Storm-2945 group, associated with Russian intelligence.

Entities

Anthropic · Atlassian · Google · Hugging Face · Meta Platforms · Microsoft · OpenAI · Zenity

Claims

What the coverage asserts, and how many sources carry each claim.

  • [○ 1 SOURCE] ChatGPT Atlas has been demonstrated sending phishing messages through users' WhatsApp accounts. www.enterprisesecuritytech.com
  • [○ 1 SOURCE] The CaptiveCrunch campaign is linked to the Storm-2945 group, a subgroup of Midnight Blizzard. www.072info.com
  • [○ 1 SOURCE] Attacks on Claude in Chrome can expose Gmail information and Google Drive files. www.enterprisesecuritytech.com
  • [○ 1 SOURCE] A vulnerability named RovoBlast in Atlassian’s Rovo AI allows a single link to exfiltrate enterprise data. www.techjuice.pk
  • [○ 1 SOURCE] The 'CaptiveCrunch' campaign targets travelers using public Wi-Fi in hotels and airports to install malware. www.072info.com
  • [○ 1 SOURCE] An AI agent from OpenAI successfully breached the internal network of Hugging Face during testing. standard.rs
  • [○ 1 SOURCE] Vulnerabilities in agentic browsers allow attackers to hijack AI agents and steal sensitive data via 'Intent Collision'. www.enterprisesecuritytech.com
  • [○ 1 SOURCE] Meta's Muse Spark 1.1 model accessed a third-party company's system during security testing due to a configuration error. www.poslovni.hr