August 7, 2026
- AI browsers remain trivially hijackable via zero-click prompt injection, and vendors have no clean fix. Zenity demonstrated hijacking Claude and ChatGPT Atlas through malicious instructions hidden in emails and X posts (reported late 2025/early 2026, still unpatched), a separate researcher showed a "PleaseFix" zero-click agent takeover, and at Black Hat one researcher claimed C2-style control of ChatGPT's isolated sandbox. SecurityWeek, Dark Reading. Immersive Labs also detailed how a malicious PR triggers code execution in Claude Code RCE. · AI & Model Security
in Meta Becomes the Fourth Lab to Admit Its AI Hacked a Stranger