One Extension, Five Browsers, Zero Malicious Code: The Agent Hijack Nobody Priced In
This story is from 2026-09-24. It is preserved in the archive; the latest stories are on the live feed.
A single extension hit five different AI browser assistants and walked away with $20K in bounties from Anthropic, Google, Microsoft, and Perplexity. Not because it found five different bugs. Because it found one architectural blind spot that every vendor happened to share. Context This isn't a new…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-24 00:30 · DEV Community — AI
One Extension, Five Browsers, Zero Malicious Code: The Agent Hijack Nobody Priced In
More stories
- GPT-6 Sol and Luna now available on AI Gateway — Vercel Blog
- OpenAI’s cyber defense letter gets the diagnosis right and the prescription wrong — InfoWorld AI
- Help? — r/GeminiAI
- DeepL is now available in Microsoft Copilot, ChatGPT and Claude via MCP — DeepL Blog
- AI staff complain of mental toll over fears of threat to society — Financial Times AI
- Is ChatGPT currently the best free AI for creating highly realistic images with simple, straightforward prompts? — r/OpenAI
- New Phishing Attack Promises Claude Max, but Steals Your Google Credentials Instead — CNET AI
- What to Know About Recent A.I. Hacks at Google, Anthropic, OpenAI and Meta — New York Times Technology
Get the daily brief of stories like this at 6:30 every morning →