Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Stock market rotation out of AI is just getting started, analysts say

Stock market rotation out of AI is just getting started, analysts say

13 December 2025
2 U.S. service members and one American civilian killed in Islamic State ambush in Syria

2 U.S. service members and one American civilian killed in Islamic State ambush in Syria

13 December 2025
Early Buzz For ‘Highguard,’ The Game Awards Closer, Is Quite Poor

Early Buzz For ‘Highguard,’ The Game Awards Closer, Is Quite Poor

13 December 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Password-Stealing AI HashJack Threat To Web Browsers Confirmed
Innovation

Password-Stealing AI HashJack Threat To Web Browsers Confirmed

Press RoomBy Press Room26 November 20253 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Password-Stealing AI HashJack Threat To Web Browsers Confirmed

Two significant current security concerns involve web browser vulnerabilities and AI-related threats. So, when security researchers issue a warning about something that combines both in one handy attack scenario, it’s time for your ears to prick up. HashJack is the latest hacking technique that, the researchers said, can enable attackers to do everything from spread misinformation to steal your credentials. Here’s what you need to know.

The AI HashJack Attack Explained

AI prompt injection attacks are nothing new; they are as old as generative AI services themselves. Google has developed many resources and tools to fight just such prompt-injection risks as they apply to Gemini. Cybercriminals, however, continue to find ways around the protections put in place to prevent the use of malicious prompts in all use-case scenarios. There are even systems, such as GhostGPT, that cybercriminals have flocked to for the purposes of creating malware and phishing scam messaging alike.

Now security researchers from the Cato CTRL Threat Research team at Cato Networks have confirmed the latest addition to the AI-hacker toolset: HashJack.

“HashJack is a newly discovered indirect prompt injection technique that conceals malicious instructions after the # in legitimate URLs,” Vitaly Simonovich, a senior security researcher with Cato CTRL, said. “When AI browsers send the full URL, including the fragment, to their AI assistants,” Simonovich warned, “those hidden prompts get executed.” This is actually as nasty as it sounds, because by so doing it can enable a variety of malicious and criminal behaviors.

AI HashJack Attack Scenarios

The ability of HashJack to effectively weaponize ordinary websites is, as far as I am aware, unique so far in such threat types. The web servers are none the wiser that everything after the # symbol in an otherwise entirely legitimate URL gets processed by AI browsers, and not ordinary ones, to facilitate the prompt injection attack with complete stealth.

The Cato report has explored a total of six potential HashJack attack scenarios, namely: callback phishing, data exfiltration, misinformation, malware guidance, medical harm, and credential theft.

Callback phishing involves an attacker using the hidden prompts to direct the browser to “add security or support links that point to threat actor resources, including phone numbers and WhatsApp groups that look official,” Simonovich said.

Data exfiltration involves using the hidden fragment to tell an agentic browser to go fetch a threat actor URL and “append user context such as account name, account number, transaction history, profile email, and phone number as parameters,” Simonovich said.

Credential theft involves the embedding of “convincing security steps or re-login instructions in URL fragments that instruct the AI browser assistant to insert a threat actor-controlled login link into responses.”

Simonovich has posted a timeline of reporting and remediation for the AI HashJack attack vulnerability, showing Google Gemini as yet unresolved, Microsoft CoPilot for Edge fixed on October 27, and Perplexity (Comet) fixed on November 18. I have reached out to Google for further clarification.

AI Hack Cato Networks Hack Hacking AI hacking AI browsers Hasgtag attack HashJack Hashtag hashtag hack Web Browser security
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Early Buzz For ‘Highguard,’ The Game Awards Closer, Is Quite Poor

Early Buzz For ‘Highguard,’ The Game Awards Closer, Is Quite Poor

13 December 2025
Apple Confirms iPhone Attacks—All Users Must Update Now

Apple Confirms iPhone Attacks—All Users Must Update Now

13 December 2025
Samsung Galaxy S26 Release Date: What’s Happening In May?

Samsung Galaxy S26 Release Date: What’s Happening In May?

13 December 2025
Google’s Play Update—Bad News For Most Samsung Users

Google’s Play Update—Bad News For Most Samsung Users

13 December 2025
WWE SmackDown December 12, 2025 Results: Highlights And Takeaways

WWE SmackDown December 12, 2025 Results: Highlights And Takeaways

13 December 2025
‘NYT Mini’ Clues And Answers For Saturday, December 13

‘NYT Mini’ Clues And Answers For Saturday, December 13

13 December 2025
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

30 December 2024
John Summit went from working 9 a.m. to 9 p.m. in a ,000 job to a multimillionaire DJ—‘I make more in one show than I would in my entire accounting career’

John Summit went from working 9 a.m. to 9 p.m. in a $65,000 job to a multimillionaire DJ—‘I make more in one show than I would in my entire accounting career’

18 October 2025
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
SpaceX sets 0 billion valuation, confirms 2026 IPO plans

SpaceX sets $800 billion valuation, confirms 2026 IPO plans

13 December 20250 Views
Apple Confirms iPhone Attacks—All Users Must Update Now

Apple Confirms iPhone Attacks—All Users Must Update Now

13 December 20250 Views
Wisconsin couple’s ACA health plan soars from  a month to ,600 as subsidies expire

Wisconsin couple’s ACA health plan soars from $2 a month to $1,600 as subsidies expire

13 December 20250 Views
Samsung Galaxy S26 Release Date: What’s Happening In May?

Samsung Galaxy S26 Release Date: What’s Happening In May?

13 December 20250 Views
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Stock market rotation out of AI is just getting started, analysts say

Stock market rotation out of AI is just getting started, analysts say

13 December 2025
2 U.S. service members and one American civilian killed in Islamic State ambush in Syria

2 U.S. service members and one American civilian killed in Islamic State ambush in Syria

13 December 2025
Early Buzz For ‘Highguard,’ The Game Awards Closer, Is Quite Poor

Early Buzz For ‘Highguard,’ The Game Awards Closer, Is Quite Poor

13 December 2025
Most Popular
ACA subsidies are about to expire, and Congress still has no consensus solution

ACA subsidies are about to expire, and Congress still has no consensus solution

13 December 20250 Views
SpaceX sets 0 billion valuation, confirms 2026 IPO plans

SpaceX sets $800 billion valuation, confirms 2026 IPO plans

13 December 20250 Views
Apple Confirms iPhone Attacks—All Users Must Update Now

Apple Confirms iPhone Attacks—All Users Must Update Now

13 December 20250 Views
© 2025 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.