Cybersecurity Today

AI Browser Steals Data

Oct 7, 2025
A startling flaw in the Perplexity Comet AI browser allows malicious prompts to turn it into a data thief with one click. Meanwhile, Discord reveals a data breach that exposes users' personal information via a compromised third-party vendor. Researchers also note a staggering 500% surge in scans targeting Palo Alto's login portals, indicating possible future attacks. Finally, the US Department of Defense’s decision to cut cybersecurity training raises alarm about maintaining defense readiness amidst rising cyber threats.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

AI Browsers Can Act As Insider Threats

  • AI-native browsers can become insider threats when agent prompts and memory access are hijacked by a crafted URL.
  • These tools bypass traditional defenses because the browser already has legitimate access to connected services.
ANECDOTE

Scamlexity Shows This Problem Isn't New

  • Shipley recalls a 2020 attack called Scamlexity that tricked AI browsers into interacting with phishing pages.
  • He uses this history to show AI browser weaknesses are not new and can repeat without fixes.
ADVICE

Separate AI Agent Access From User Credentials

  • Separate agentic AI access from legitimate human access to reduce risk of silent data exfiltration.
  • Build security into AI tools from day one to prevent prompts and memory access being hijacked.
Get the Snipd Podcast app to discover more snips from this episode
Get the app