View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

AI Browsers Vulnerable to Zero-Click Prompt-Injection Hijacking

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • AI Browsers Remain Vulnerable to Zero-Click Prompt-Injection Hijacking AI browsers remain vulnerable to prompt-injection attacks that can hijack browser agents.

    • AI browsers from major vendors are affected.
    • Malicious instructions hidden in content supplied to AI browsers can control their agents.
    • The attacks can work without user interaction.
    • Existing security guardrails do not fully prevent the prompt injections. ๐Ÿ“Ž Coverage: darkreading.com ยท ๐Ÿ‘ via Dark Reading (+1)
  • Automated SSH Campaign Establishes Persistence Within 22 Seconds An automated SSH campaign established persistent access within 22 seconds.

    • Internet-facing Linux SSH servers using weak or compromised credentials were targeted.
    • Attackers injected an SSH key, changed the root password, removed the .ssh directory, and cleared /etc/hosts.deny.
    • Automation used credentials including root / Aa123123123 and repeated a fixed post-authentication command sequence.
    • Observed indicators included 163.7.8.79, 80.94.92.184, 80.94.92.186, 80.94.92.171, and SSH key hash a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2. ๐Ÿ“Ž Coverage: isc.sans.edu ยท ๐Ÿ‘ via SANS ISC
  • Ransom Cartel creator Maksim Silnikau sentenced to 16 years in prison Ransom Cartel creator Maksim Silnikau was sentenced to 16 years in prison.

    • Ransom Cartel affiliates attacked at least 18 companies worldwide between 2021 and 2023.
    • The operation encrypted corporate systems, stole data, and demanded ransoms to restore access or prevent leaks.
    • Prosecutors said the group attempted to extort at least $5.2 million, with known victim losses exceeding $6.7 million.
    • Silnikau recruited affiliates through cybercrime forums and supplied stolen credentials and ransomware encryption tools.
    • An affiliate portal supported attack management, ransom negotiations, revenue sharing, and cryptocurrency-mixer payments. ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer
  • OpenAI warns autonomous AI hacks mark a watershed for computer security OpenAI warns that autonomous AI hacking marks a watershed moment for computer security.

    • OpenAI and the broader AI industry are affected.
    • OpenAI employees warned that autonomous hacking capabilities are challenging existing security safeguards. ๐Ÿ“Ž Coverage: cybersecuritydive.com ยท ๐Ÿ‘ via Cybersecurity Dive

๐Ÿ”“ CVEs & KEV

  • CVE-2026-71319 โ€” CVSS 9.6 โ€” Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code ExecutionNu...
  • CVE-2026-71315 โ€” CVSS 8.2 โ€” Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddlewa...
  • CVE-2026-71320 โ€” CVSS 8.1 โ€” Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nux...
  • CVE-2026-71321 โ€” CVSS 7.5 โ€” Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endp...
  • CVE-2026-71316 โ€” CVSS 7.5 โ€” Nuxt runtime payload cache discloses another user's SSR data across users and...
  • CVE-2026-71314 โ€” CVSS 7.5 โ€” Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in is...
  • CVE-2026-71313 โ€” CVSS 6.9 โ€” rclone: Local Encoding Path Traversalrclone is a command-line program to sync...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check