Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
What slowdown? OpenAI, Anthropic release dueling models as AI price wars heat up

What slowdown? OpenAI, Anthropic release dueling models as AI price wars heat up

22 September 2026
The 10-year Treasury yield just hit 5% for the first time since 2007 — is a 1970s-style ‘stagflation’ on the return?

The 10-year Treasury yield just hit 5% for the first time since 2007 — is a 1970s-style ‘stagflation’ on the return?

22 September 2026
​Enterprise AI Needs A New Change Management Model

​Enterprise AI Needs A New Change Management Model

22 September 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Password-Stealing AI HashJack Threat To Web Browsers Confirmed
Innovation

Password-Stealing AI HashJack Threat To Web Browsers Confirmed

Press RoomBy Press Room26 November 20253 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Password-Stealing AI HashJack Threat To Web Browsers Confirmed

Two significant current security concerns involve web browser vulnerabilities and AI-related threats. So, when security researchers issue a warning about something that combines both in one handy attack scenario, it’s time for your ears to prick up. HashJack is the latest hacking technique that, the researchers said, can enable attackers to do everything from spread misinformation to steal your credentials. Here’s what you need to know.

The AI HashJack Attack Explained

AI prompt injection attacks are nothing new; they are as old as generative AI services themselves. Google has developed many resources and tools to fight just such prompt-injection risks as they apply to Gemini. Cybercriminals, however, continue to find ways around the protections put in place to prevent the use of malicious prompts in all use-case scenarios. There are even systems, such as GhostGPT, that cybercriminals have flocked to for the purposes of creating malware and phishing scam messaging alike.

Now security researchers from the Cato CTRL Threat Research team at Cato Networks have confirmed the latest addition to the AI-hacker toolset: HashJack.

“HashJack is a newly discovered indirect prompt injection technique that conceals malicious instructions after the # in legitimate URLs,” Vitaly Simonovich, a senior security researcher with Cato CTRL, said. “When AI browsers send the full URL, including the fragment, to their AI assistants,” Simonovich warned, “those hidden prompts get executed.” This is actually as nasty as it sounds, because by so doing it can enable a variety of malicious and criminal behaviors.

AI HashJack Attack Scenarios

The ability of HashJack to effectively weaponize ordinary websites is, as far as I am aware, unique so far in such threat types. The web servers are none the wiser that everything after the # symbol in an otherwise entirely legitimate URL gets processed by AI browsers, and not ordinary ones, to facilitate the prompt injection attack with complete stealth.

The Cato report has explored a total of six potential HashJack attack scenarios, namely: callback phishing, data exfiltration, misinformation, malware guidance, medical harm, and credential theft.

Callback phishing involves an attacker using the hidden prompts to direct the browser to “add security or support links that point to threat actor resources, including phone numbers and WhatsApp groups that look official,” Simonovich said.

Data exfiltration involves using the hidden fragment to tell an agentic browser to go fetch a threat actor URL and “append user context such as account name, account number, transaction history, profile email, and phone number as parameters,” Simonovich said.

Credential theft involves the embedding of “convincing security steps or re-login instructions in URL fragments that instruct the AI browser assistant to insert a threat actor-controlled login link into responses.”

Simonovich has posted a timeline of reporting and remediation for the AI HashJack attack vulnerability, showing Google Gemini as yet unresolved, Microsoft CoPilot for Edge fixed on October 27, and Perplexity (Comet) fixed on November 18. I have reached out to Google for further clarification.

AI Hack Cato Networks Hack Hacking AI hacking AI browsers Hasgtag attack HashJack Hashtag hashtag hack Web Browser security
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

​Enterprise AI Needs A New Change Management Model

​Enterprise AI Needs A New Change Management Model

22 September 2026
How To Tell The Real Ones From The Fake

How To Tell The Real Ones From The Fake

22 September 2026
The Next Frontier Of Sovereign AI Is Permission

The Next Frontier Of Sovereign AI Is Permission

22 September 2026
Enterprise Software Is Learning To Act, Not Just Record

Enterprise Software Is Learning To Act, Not Just Record

22 September 2026
Why Telecom Pricing Needs A More Flexible Model

Why Telecom Pricing Needs A More Flexible Model

22 September 2026
When AI Agents Start Covering Their Tracks

When AI Agents Start Covering Their Tracks

22 September 2026
Don't Miss
Trump’s Tariffs Will Make AI Data Centers More Expensive

Trump’s Tariffs Will Make AI Data Centers More Expensive

By Press Room4 April 2025

Donald Trump’s administration has gone all-in on AI: A day after his inauguration, the newly-elected…

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

27 December 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
How To Tell The Real Ones From The Fake

How To Tell The Real Ones From The Fake

22 September 20260 Views
From the Boston Tea Party to the Flock camera backlash, 250 years of Americans saying no

From the Boston Tea Party to the Flock camera backlash, 250 years of Americans saying no

22 September 20260 Views
The Next Frontier Of Sovereign AI Is Permission

The Next Frontier Of Sovereign AI Is Permission

22 September 20260 Views
Alibaba says it built the ‘most powerful AI chip in China’ as the country races with the U.S.

Alibaba says it built the ‘most powerful AI chip in China’ as the country races with the U.S.

22 September 20260 Views

Recent Posts

  • What slowdown? OpenAI, Anthropic release dueling models as AI price wars heat up
  • The 10-year Treasury yield just hit 5% for the first time since 2007 — is a 1970s-style ‘stagflation’ on the return?
  • ​Enterprise AI Needs A New Change Management Model
  • Scott Bessent: Government will not be ‘liability shield’ for AI labs amid safety standoff
  • How To Tell The Real Ones From The Fake

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
What slowdown? OpenAI, Anthropic release dueling models as AI price wars heat up

What slowdown? OpenAI, Anthropic release dueling models as AI price wars heat up

22 September 2026
The 10-year Treasury yield just hit 5% for the first time since 2007 — is a 1970s-style ‘stagflation’ on the return?

The 10-year Treasury yield just hit 5% for the first time since 2007 — is a 1970s-style ‘stagflation’ on the return?

22 September 2026
​Enterprise AI Needs A New Change Management Model

​Enterprise AI Needs A New Change Management Model

22 September 2026
Most Popular
Scott Bessent: Government will not be ‘liability shield’ for AI labs amid safety standoff

Scott Bessent: Government will not be ‘liability shield’ for AI labs amid safety standoff

22 September 20260 Views
How To Tell The Real Ones From The Fake

How To Tell The Real Ones From The Fake

22 September 20260 Views
From the Boston Tea Party to the Flock camera backlash, 250 years of Americans saying no

From the Boston Tea Party to the Flock camera backlash, 250 years of Americans saying no

22 September 20260 Views

Archives

  • September 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.