Laughing Hyena
  • Home
  • Hyena Games
  • Esports
  • NFT Gaming
  • Crypto Trends
  • Game Reviews
  • Game Updates
  • GameFi Guides
  • Shop
Tag:

flaw

How Will the Israel-Iran Conflict End? Here's What AI Models Predict
NFT Gaming

Perplexity Comet Flaw Exposed User Data to Attackers, Brave Reports

by admin August 25, 2025



In brief

  • In a demo, Comet’s AI assistant followed embedded prompts and posted private emails and codes.
  • Brave says the vulnerability remained exploitable weeks after Perplexity claimed to have fixed it.
  • Experts warn that prompt injection attacks expose deep security gaps in AI agent systems.

Brave Software has uncovered a security flaw in Perplexity AI’s Comet browser that showed how attackers could trick its AI assistant into leaking private user data.

In a proof-of-concept demo published August 20, Brave researchers identified hidden instructions inside a Reddit comment. When Comet’s AI assistant was asked to summarize the page, it didn’t just summarize—it followed the hidden commands.

Perplexity disputed the severity of the finding. A spokesperson told Decrypt the issue “was patched before anyone noticed” and said no user data was compromised. “We have a pretty robust bounty program,” the spokesperson added. “We worked directly with Brave to identify and repair it.”



Brave, which is developing its own agentic browser, maintained that the flaw remained exploitable weeks after the patch and argued Comet’s design leaves it open to further attacks.

Brave said the vulnerability comes down to how agentic browsers like Comet process web content. “When users ask it to summarize a page, Comet feeds part of that page directly to its language model without distinguishing between the user’s instructions and untrusted content,” the report explained. “This allows attackers to embed hidden commands that the AI will execute as if they were from the user.”

Prompt injection: old idea, new target

This type of exploit is known as a prompt injection attack. Instead of tricking a person, it tricks an AI system by hiding instructions in plain text.

“It’s similar to traditional injection attacks—SQL injection, LDAP injection, command injection,” Matthew Mullins, lead hacker at Reveal Security, told Decrypt. “The concept isn’t new, but the method is different. You’re exploiting natural language instead of structured code.”

Security researchers have been warning for months that prompt injection could become a major headache as AI systems gain more autonomy. In May, Princeton researchers showed how crypto AI agents could be manipulated with “memory injection” attacks, where malicious information gets stored in an AI’s memory and later acted on as if it were real.

Even Simon Willison, the developer credited with coining the term prompt injection, said the problem goes far beyond Comet. “The Brave security team reported serious prompt injection vulnerabilities in it, but Brave themselves are developing a similar feature that looks doomed to have similar problems,” he posted on X.

Shivan Sahib, Brave’s vice president of privacy and security, said its upcoming browser would include “a set of mitigations that help reduce the risk of indirect prompt injections.”

“We’re planning on isolating agentic browsing into its own storage area and browsing session, so that a user doesn’t accidentally end up granting access to their banking and other sensitive data to the agent,” he told Decrypt. “We’ll be sharing more details soon.”

The bigger risk

The Comet demo highlights a broader problem: AI agents are being deployed with powerful permissions but weak security controls. Because large language models can misinterpret instructions—or follow them too literally—they’re especially vulnerable to hidden prompts.

“These models can hallucinate,” Mullins warned. “They can go completely off the rails, like asking, ‘What’s your favorite flavor of Twizzler?’ and getting instructions for making a homemade firearm.”

With AI agents being given direct access to email, files, and live user sessions, the stakes are high. “Everyone wants to slap AI into everything,” Mullins said. “But no one’s testing what permissions the model has, or what happens when it leaks.”

Generally Intelligent Newsletter

A weekly AI journey narrated by Gen, a generative AI model.



Source link

August 25, 2025 0 comments
0 FacebookTwitterPinterestEmail
Alex Protocol Loses $8.37M In Hack Due To Security Flaw
Crypto Trends

ALEX Protocol Loses $8.37M in Hack Due to Security Flaw

by admin June 7, 2025



On June 6, 2025, ALEX, the leading Bitcoin DeFi platform on Stacks, was exploited because of a bug in its self-listing verification process. They managed to steal assets worth more than $8.37 million, including 8.4 million STX, 21.85 sBTC, 2.8 WBTC, and several types of stablecoins like USDC/USDT.

According to the official announcement from ALEXLabBTC, the issue stemmed from an on-chain limitation on Stacks, which allowed the exploit to bypass listing rules. Even though there was a breach, ALEX is covering the losses and will pay back all affected users 100% in USDC from the ALEX Lab Foundation’s funds.

On June 6, 2025, ALEX Protocol was exploited via a flaw in the self-listing verification logic (an on-chain limitation on Stacks). As a result, the attacker drained several asset pools, with the breakdown of lost assets as follows:

STX: 8,403,867.57 STX → $ 5,691,255.93
sBTC:…

— ALEX 🟧 No. 1 Bitcoin DeFi (@ALEXLabBTC) June 6, 2025

To calculate reimbursements fairly, ALEX will use the average exchange rates between 10:00 and 14:00 UTC on June 6, right around when the hack occurred. Affected users will receive a private on-chain notification by June 8, 2025, with a link to the claim form. The deadline to complete and confirm the wallet address is June 10, 2025.

Once verified, USDC payouts will be distributed within seven business days. The team emphasized that its priority is to make every user whole as quickly as possible.

The fast and open way ALEX handled this problem shows how much it cares about its users, which may help the DeFi project recover from the incident. Since hacks are becoming more common in the crypto industry, ALEX’s promise to fully reimburse users is very reassuring.

Also Read: Ukraine Police Arrest Hacker for $4.5M Cryptojacking Attack





Source link

June 7, 2025 0 comments
0 FacebookTwitterPinterestEmail
WordPress logo on mobile
Gaming Gear

Critical security flaw could leave over 100,000 WordPress sites at risk

by admin May 29, 2025



  • A flaw in TI WooCommerce Wishlist allows threat actors to upload arbitrary files
  • Since the files can be malicious, they could fully take over a website
  • A patch is not yet released, so users should take care

A critical-severity vulnerability in a popular WordPress plugin is possibly exposing hundreds of thousands of websites to different risks, including complete website takeover.

Security researchers from Patchstack have claimed TI WooCommerce Wishlist carried an arbitrary file upload flaw, which allowed actors to upload malicious files to the underlying server without authentication.

The vulnerability is now tracked as CVE-2025-47577, and has a severity score of 10/10 (critical).


You may like

Reading the calendar

The TI WooCommerce Wishlist plugin is an extension for WooCommerce stores that allows users to create and manage wishlists, saving and sharing their favorite products.

Besides the social sharing options, the plugin comes with AJAX-based functionality, multiple wishlist support in the premium version, email notifications, and more.

According to The Hacker News, it has more than 100,000 active installations, meaning that the potential attack surface is rather large. To make matters worse, these are e-commerce sites, where visitors usually come to spend money, further compounding the risk.

At press time, the newest version of the plugin is 2.9.2, last updated six months ago. Since the patch has not yet been released, users who fear an attack are advised to disable and remove the plugin until a fix is released.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

The silver lining here is that successful exploitation is only possible on websites that also have the WC Fields Factory plugin installed and running, and the integration is enabled on the TI WooCommerce Wishlist plugin.

WC Fields Factory is a free WooCommerce plugin that allows store owners to add custom fields to product pages, variations, checkout forms, and the WordPress admin interface.

It supports different field types such as text, number, email, date picker, and more. The plugin allows for dynamic pricing adjustments based on field inputs, field visibility rules, and role-based access controls, as well, and it offers a drag-and-drop form designer.

You might also like



Source link

May 29, 2025 0 comments
0 FacebookTwitterPinterestEmail

Categories

  • Crypto Trends (957)
  • Esports (720)
  • Game Reviews (646)
  • Game Updates (840)
  • GameFi Guides (949)
  • Gaming Gear (907)
  • NFT Gaming (940)
  • Product Reviews (895)

Recent Posts

  • Borderlands 4 adds Razer Sensa HD haptics and Chroma RGB to its arsenal
  • Shiba Inu Fragile Despite Billions in Accumulation: Maxi Doge Is Better
  • Today in video games – 26th August: the Gamescom mop-up continues as the industry takes a breath
  • Saudi AI Firm Launches Halal Chatbot
  • Sonic Crossworlds Is Doing Way More For Me Than Mario Kart

Recent Posts

  • Borderlands 4 adds Razer Sensa HD haptics and Chroma RGB to its arsenal

    August 26, 2025
  • Shiba Inu Fragile Despite Billions in Accumulation: Maxi Doge Is Better

    August 26, 2025
  • Today in video games – 26th August: the Gamescom mop-up continues as the industry takes a breath

    August 26, 2025
  • Saudi AI Firm Launches Halal Chatbot

    August 26, 2025
  • Sonic Crossworlds Is Doing Way More For Me Than Mario Kart

    August 26, 2025

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

About me

Welcome to Laughinghyena.io, your ultimate destination for the latest in blockchain gaming and gaming products. We’re passionate about the future of gaming, where decentralized technology empowers players to own, trade, and thrive in virtual worlds.

Recent Posts

  • Borderlands 4 adds Razer Sensa HD haptics and Chroma RGB to its arsenal

    August 26, 2025
  • Shiba Inu Fragile Despite Billions in Accumulation: Maxi Doge Is Better

    August 26, 2025

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

@2025 laughinghyena- All Right Reserved. Designed and Developed by Pro


Back To Top
Laughing Hyena
  • Home
  • Hyena Games
  • Esports
  • NFT Gaming
  • Crypto Trends
  • Game Reviews
  • Game Updates
  • GameFi Guides
  • Shop

Shopping Cart

Close

No products in the cart.

Close