Connect with us

Tech

Password-Stealing AI HashJack Threat To Web Browsers Confirmed

Published

on


Two significant current security concerns involve web browser vulnerabilities and AI-related threats. So, when security researchers issue a warning about something that combines both in one handy attack scenario, it’s time for your ears to prick up. HashJack is the latest hacking technique that, the researchers said, can enable attackers to do everything from spread misinformation to steal your credentials. Here’s what you need to know.

ForbesAmazon Issues Attack Alert — 300 Million Customers Are At Risk

The AI HashJack Attack Explained

AI prompt injection attacks are nothing new; they are as old as generative AI services themselves. Google has developed many resources and tools to fight just such prompt-injection risks as they apply to Gemini. Cybercriminals, however, continue to find ways around the protections put in place to prevent the use of malicious prompts in all use-case scenarios. There are even systems, such as GhostGPT, that cybercriminals have flocked to for the purposes of creating malware and phishing scam messaging alike.

Now security researchers from the Cato CTRL Threat Research team at Cato Networks have confirmed the latest addition to the AI-hacker toolset: HashJack.

“HashJack is a newly discovered indirect prompt injection technique that conceals malicious instructions after the # in legitimate URLs,” Vitaly Simonovich, a senior security researcher with Cato CTRL, said. “When AI browsers send the full URL, including the fragment, to their AI assistants,” Simonovich warned, “those hidden prompts get executed.” This is actually as nasty as it sounds, because by so doing it can enable a variety of malicious and criminal behaviors.

ForbesHackers Bypass Signal, Telegram And WhatsApp Encryption To Read Messages

AI HashJack Attack Scenarios

The ability of HashJack to effectively weaponize ordinary websites is, as far as I am aware, unique so far in such threat types. The web servers are none the wiser that everything after the # symbol in an otherwise entirely legitimate URL gets processed by AI browsers, and not ordinary ones, to facilitate the prompt injection attack with complete stealth.

The Cato report has explored a total of six potential HashJack attack scenarios, namely: callback phishing, data exfiltration, misinformation, malware guidance, medical harm, and credential theft.

Callback phishing involves an attacker using the hidden prompts to direct the browser to “add security or support links that point to threat actor resources, including phone numbers and WhatsApp groups that look official,” Simonovich said.

Data exfiltration involves using the hidden fragment to tell an agentic browser to go fetch a threat actor URL and “append user context such as account name, account number, transaction history, profile email, and phone number as parameters,” Simonovich said.

Credential theft involves the embedding of “convincing security steps or re-login instructions in URL fragments that instruct the AI browser assistant to insert a threat actor-controlled login link into responses.”

ForbesDo Not Download These Windows Security Updates, Experts Warn

Simonovich has posted a timeline of reporting and remediation for the AI HashJack attack vulnerability, showing Google Gemini as yet unresolved, Microsoft CoPilot for Edge fixed on October 27, and Perplexity (Comet) fixed on November 18. I have reached out to Google for further clarification.



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech

Wateen and Beaconhouse Strengthen Partnership to Pioneer Digital Learning

Published

on


Wateen Telecom has strengthened its partnership with Beaconhouse Group, Pakistan’s largest network of private educational institutions, to enhance managed internet services over SD-WAN and fortify the digital learning infrastructure across the school network.

The agreement was signed by Mr. Ali Ahmad Khan, Chief Operating Officer, Beaconhouse, and Mr. Adil Rashid, CEO, Wateen Telecom.

The signing ceremony was attended by senior representatives from both organizations.

This collaboration builds on a longstanding foundation that reflects a shared commitment to enabling future-ready learning environments powered by secure, scalable, and reliable connectivity – pioneering the future of digital education in Beaconhouse schools across Pakistan.

The upgraded SD-WAN and Wi-Fi infrastructure will enhance classroom connectivity, support high-density usage, and create a more seamless experience for students accessing digital tools, cloud-based apps, and online learning resources.

This initiative reflects Wateen’s ongoing focus on strengthening Pakistan’s digital education landscape, enabling schools to deliver richer, more reliable learning experiences through modern, high-performance connectivity.





Source link

Continue Reading

Tech

Vivo X300 Pro Is An iPhone 17 Pro Rival With A Bigger Battery And Zeiss-Tuned Cameras

Published

on


Vivo launched the X300 and X300 Pro at an event in Shanghai, China on October 13, followed by an India debut last week. The Vivo X300 Pro takes on the iPhone 17 Pro, Oppo Find X9 Pro, and Samsung Galaxy S25 Ultra with an improved camera system, the latest MediaTek processor, and a familiar design language – something Oppo and OnePlus have deviated from this year.

The new flagship sports a large circular camera module on the back but flattens its sides. Vivo has steadily removed curves from its premium phones, a move that might bother some people. However, this design offers better grip than the slippery Vivo X100 Pro and is nowhere near as sharp as the Samsung Galaxy S25 Ultra. While the phone is heavy at 228 grams, it feels comfortable thanks to good weight distribution. It retains the IP68 and IP69 dust and water resistance ratings from last year.

There is no annoying Camera Control copy here, but you do get an Action Button clone on the left side. It supports both a standard long-press and a double-press trigger, which is currently not possible on Apple iPhones.. For example, I have set my unit to trigger DND with a long press and enable the flashlight with a double press.

The Vivo X300 Pro features a 6.78-inch LTPO AMOLED display with thinner bezels, making the device slightly slimmer and shorter than its predecessor. Colors are vivid, and the screen is easily legible in bright environments. It supports a 1,260 x 2,800 resolution with 452ppi pixel density, a dynamic 120Hz refresh rate, and a 94.85 percent screen-to-body ratio that makes HDR content look more immersive than before.

Under the hood, the Vivo flagship is powered by the top-tier MediaTek Dimensity 9500 chipset, paired with 16GB of LPDDR5X Ultra RAM and 512GB of UFS 4.1 storage. It offers smooth performance in day-to-day use and handles demanding games without overheating. You will notice the thermal improvement over last year’s Dimensity 9400 and recent rivals during extended gaming sessions.

Vivo continues its photography lead with a triple rear camera setup. The X300 Pro sports a 50MP Sony LYT-828 main camera, a 200MP telephoto sensor with 3.5x optical zoom, and a 50MP JN1 sensor for ultrawide shots.

As for the camera quality, you get good color vibrancy and white balance in daylight shots. Compared to the Vivo X200 Pro, the new model manages highlights and shadows better, offering more detail in challenging low-light environments. Portrait shots look as good as before, though there are occasional inconsistencies in processing. And like before, there are plenty of Zeiss effects and filters to play around with.

It also gets a Telephoto Extender Kit that supports 2.35x zoom. Co-engineered with Zeiss, the kit includes a lens, adapter ring, mounting parts, and a matching phone case. Unlike the Oppo-Hasselblad Teleconverter Kit, Vivo’s Extender Kit works with both the X300 Pro and the standard X300.

The Vivo X300 Pro packs a big 6,510mAh battery in China and India, though European models will ship with a smaller 5,440mAh cell. Both versions support 90W wired fast charging and 40W wireless charging. Regardless of the region, it should last an entire day with ease on moderate use. However, don’t expect it have multi-day endurance of the Oppo Find X9 Pro or the OnePlus 15.

For the first time, Vivo is bringing its OriginOS out of China. The Vivo X300 Pro runs Android 16-based OriginOS 6 globally. It offers a modern design, better UI uniformity, and is a clear upgrade over Funtouch OS.

You get iOS 26-like design elements, including translucent effects and a Dynamic Island-style feature for multitasking. For instance, you can select multiple photos from the gallery, drag them to the top of the screen to reveal shareable options, and drop them into an app like WhatsApp. It is a smart implementation of an existing concept.

Vivo X300 Pro: Price And Availability

The Vivo X300 Pro is priced at INR 1,09,999 for the single 16GB RAM + 512GB storage variant in India. It is available for pre-booking now and will go on sale in Dune Gold and Elite Black starting December 10. Like previous Vivo flagships, the X300 series will not be released in the U.S.



Source link

Continue Reading

Tech

Zuma Resources Approves Asset Sale, Shifts Focus to Tech and EV Investments

Published

on



Zuma Resources Limited (formerly Bilal Fibres Limited) has announced a strategic shift in its business direction, with the Board of Directors approving a new focus on investments and partnerships across technology, AI-enabled services, electric vehicles (EV), healthcare, e-commerce, and other sectors.

In a notice to the Pakistan Stock Exchange, the company said its board, at a meeting held on December 5, 2025, also approved the sale of land, buildings, plant, machinery, and other fixed assets.

The asset sale is being carried out in compliance with an order from the Lahore High Court to settle outstanding bank liabilities.

Additionally, the board approved the financial statements for the year ended June 30, 2025, and authorized management to convene the annual general meeting on December 31, 2025.

Zuma Resources, which recently rebranded from Bilal Fibres Limited, said it will keep stakeholders informed of further developments as it pursues its new investment strategy and completes the court-mandated asset sale.





Source link

Continue Reading

Trending