Connect with us

Technologies

Perplexity’s Comet AI Web Browser Had a Major Security Vulnerability

Essentially, invisible prompts on websites could make Comet’s AI assistant do things it wasn’t asked to do.

Comet, Perplexity’s new AI-powered web browser, recently suffered from a significant security vulnerability, according to a blog post last week from Brave, a competing web browser company. The vulnerability has since been fixed, but it points to the challenges of incorporating large language models into web browsers.

Unlike traditional web browsers, Comet has an AI assistant built in. This assistant can scan the page you’re looking at, summarize its contents or perform tasks for you. The problem is that Comet’s AI assistant is built on the same technology as other AI chatbots, like ChatGPT. 

AI chatbots can’t think and reason the same way humans can, and if they read a piece of content meant to manipulate its output, it may end up following through. This is known as prompt engineering. 

(Disclosure: Ziff Davis, CNET’s parent company, in April filed a lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.)

A representative for Brave didn’t immediately respond to a request for comment. 

AI companies try to mitigate the manipulation of AI chatbots, but that can be tricky, as bad actors always look at novel ways to break through protections. 

«This vulnerability is fixed,» said Jesse Dwyer, Perplexity’s head of communications in a statement. «We have a pretty robust bounty program, and we worked directly with Brave to identify and repair it.»

Test used hidden text on Reddit

In its testing, Brave set up a Reddit page with invisible text on the screen and asked Comet to summarize the on-screen content. As the AI processed the page’s content, it couldn’t distinguish between the malicious prompts and began feeding Brave’s testers sensitive information. 

In this case, the hidden text enabled Comet’s AI assistant to navigate to a user’s Perplexity account, extract the associated email address, and navigate to a Gmail account. The AI agent was essentially acting as an actual user, meaning that traditional security methods weren’t working. 

Brave warns that this type of prompt injection can go further, accessing bank accounts, corporate systems, private emails and other services. 

Brave’s senior mobile security engineer, Artem Chaikin, and VP of privacy and security, Shivan Kaul Sahib, laid out a list of possible fixes. First, AI web browsers should always treat page content as untrusted. AI models should check to make sure they’re following user intent. The model should always double-check with the user to ensure interactions are correct, and agentic browsing mode should only turn on when the user wants it to.

Brave’s blog post is the first in a series regarding challenges facing AI web browsers. Brave also has an AI assistant, Leo, embedded in its browser. 

AI is increasingly embedded in all parts of technology, from Google searches to toothbrushes. While having an AI assistant is handy, these new technologies have different security vulnerabilities. 

In the past, hackers needed to be expert coders to break into systems. When dealing with AI, however, it’s possible to use squirrely natural language to get past built-in protections. 

Also, since many companies rely on major AI models, such as ones from OpenAI, Google and Meta, any vulnerabilities in those systems could extend to companies using those same models. AI companies haven’t been open about these types of security vulnerabilities as doing so might tip off hackers, giving them new avenues to exploit. 

Technologies

Verum Messenger: How to Protect Your Personal Data and Why Choosing a Secure Messenger Matters

Verum Messenger: How to Protect Your Personal Data and Why Choosing a Secure Messenger Matters

A major data leak has been reported involving users of the Russian messenger MAX. Hackers claimed to have obtained the platform’s entire database, which includes 46,203,590 records. To prove their claims, they published part of the stolen data publicly.

According to preliminary information, the attackers gained access to users’ personal details, including contact numbers, chats, IP addresses, and other sensitive data. Cybersecurity experts warn that such incidents can lead to serious consequences — from account takeovers and extortion to large-scale phishing attacks.

Why these leaks happen

The main cause of such breaches is the storage of personal user data on servers without adequate protection or encryption. If attackers gain access to these servers, users’ information becomes fully exposed.

Additionally, many popular messaging apps require users to register with a phone number and provide extra personal information, increasing the amount of data that can be stolen.

How to reduce the risks

The only reliable way to protect your personal messages and data is to use messaging platforms that do not store personal information on their servers and rely on true end-to-end encryption.

One such solution is Verum Messenger — a next-generation app built on the principle of maximum privacy. The platform:

  • does not store users’ personal data;
  • uses unique encryption keys generated locally on the user’s device;
  • does not require a phone number or other personal information to register;
  • has no access to messages, calls, or files;
  • provides effective anti-spam and anti-scam protection;
  • offers private chats and group channels with flexible security settings.

Even in the event of a server breach, attackers would not be able to access message content — because encryption keys simply do not exist on the company’s side.

Freedom of communication without the risk of leaks

In addition to its strong security foundation, Verum Messenger offers a built-in ecosystem of tools — from encrypted email Verum Mail and an integrated VPN for anonymous connections to free crypto mining with Verum Coin and eSIM connectivity in over 150 countries worldwide.

As data breaches become increasingly common, choosing a secure messenger is no longer just about convenience — it’s about personal safety.

Continue Reading

Technologies

Today’s NYT Mini Crossword Answers for Monday, Oct. 20

Here are the answers for The New York Times Mini Crossword for Oct. 20.

Looking for the most recent Mini Crossword answer? Click here for today’s Mini Crossword hints, as well as our daily answers and hints for The New York Times Wordle, Strands, Connections and Connections: Sports Edition puzzles.


Need some help with today’s Mini Crossword? It was a tough one for a change! That 1-Across is going to slyly trick you as to what a mouse is. So if you need the answers, read on. And if you could use some hints and guidance for daily solving, check out our Mini Crossword tips.

If you’re looking for today’s Wordle, Connections, Connections: Sports Edition and Strands answers, you can visit CNET’s NYT puzzle hints page.

Read more: Tips and Tricks for Solving The New York Times Mini Crossword

Let’s get to those Mini Crossword clues and answers.

Mini across clues and answers

1A clue: Sound from a mouse
Answer: CLICK

6A clue: Many-headed serpent killed by Hercules
Answer: HYDRA

7A clue: View from a cruise ship window
Answer: OCEAN

8A clue: «See ya later!»
Answer: PEACE

9A clue: Animal whose antlers can grow up to an inch per day
Answer: ELK

Mini down clues and answers

1D clue: Dice, e.g.
Answer: CHOP

2D clue: French for «high school»
Answer: LYCEE

3D clue: 10 out of 10
Answer: IDEAL

4D clue: Sound from a bat
Answer: CRACK

5D clue: «Citizen ___»
Answer: KANE

Continue Reading

Technologies

Today’s NYT Connections: Sports Edition Hints and Answers for Oct. 20, #392

Here are hints and the answers for the NYT Connections: Sports Edition puzzle for Oct. 20, No. 392.

Looking for the most recent regular Connections answers? Click here for today’s Connections hints, as well as our daily answers and hints for The New York Times Mini Crossword, Wordle and Strands puzzles.


Today’s Connections: Sports Edition has a category for all the Windy City residents out there. If you’re struggling but still want to solve it, read on for hints and the answers.

Connections: Sports Edition is published by The Athletic, the subscription-based sports journalism site owned by the Times. It doesn’t show up in the NYT Games app but appears in The Athletic’s own app. Or you can play it for free online.

Read more: NYT Connections: Sports Edition Puzzle Comes Out of Beta

Hints for today’s Connections: Sports Edition groups

Here are four hints for the groupings in today’s Connections: Sports Edition puzzle, ranked from the easiest yellow group to the tough (and sometimes bizarre) purple group.

Yellow group hint: Deep-dish pizza, anyone?

Green group hint: Duke it out.

Blue group hint: College division.

Purple group hint: «Go to your ____!»

Answers for today’s Connections: Sports Edition groups

Yellow group: Chicago teams.

Green group: With «weight,» combat sport divisions.

Blue group: American Conference teams.

Purple group: ____ room.

Read more: Wordle Cheat Sheet: Here Are the Most Popular Letters Used in English Words

What are today’s Connections: Sports Edition answers?

The yellow words in today’s Connections

The theme is Chicago teams. The four answers are Bears, Bulls, Cubs and Sky.

The green words in today’s Connections

The theme is with «weight,» combat sport divisions. The four answers are bantam, feather, fly and heavy.

The blue words in today’s Connections

The theme is American Conference teams. The four answers are Blazers, Chanticleers, Green Wave and Pirates.

The purple words in today’s Connections

The theme is ____ room.  The four answers are dressing, film, green and locker.

Continue Reading

Trending

Exit mobile version