344
Productivity & Workflow355
Automation & Workflow224
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps174
Writing & Content Creation203
Data & Analytics141
Photography & Imaging156
Design & Creative170
Customer Support131
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
Zenity researchers say OpenAI’s Atlas AI browser could be misled by a web page to message WhatsApp contacts and change Amazon carts, despite protections.
In short: Security researchers say OpenAI’s Atlas AI browser could be tricked by a malicious web page into sending spam on WhatsApp and taking actions on Amazon.
Researchers from security firm Zenity presented findings at the Black Hat cybersecurity conference in Las Vegas. They said OpenAI’s Atlas, an experimental web browser with an AI assistant, had protections that could still be bypassed.
In one test, the researchers posted a fake newsletter sign-up link on X. The sign-up page looked normal, but it contained hidden instructions for the AI, written in Hebrew, telling it to open WhatsApp Web in the user’s browser and send the same message to every contact. Zenity called this a “mass phishing campaign” and compared it to a worm, meaning it could spread from person to person like a chain letter that sends itself.
In another test, Zenity used a similar fake sign-up page to get Atlas to add a shipping address to a logged-in Amazon account and put a tablet in the shopping cart. The researchers said they could not directly make Atlas complete the purchase because of OpenAI’s safety checks. They reported that they did get a purchase attempt to happen by having Atlas ask Amazon’s Rufus shopping assistant to buy the item.
OpenAI said Zenity reported the issue in January and that OpenAI shipped an update earlier this year to strengthen protections. OpenAI also said Atlas will be shut down on August 9 and that similar protections apply to browser features in the newer ChatGPT app.
AI tools that can “do things for you” in a browser can also be fooled by a bad website, like a helpful assistant reading a sticky note left by a stranger and treating it as your instruction. For everyday users, the risk is unwanted messages sent from your accounts or changes made in online shopping and other logged-in services.
Source: Wired