HashJack Attack Exploits AI Browsers and Assistants

HashJack Attack Exploits AI Browsers and Assistants

First seen 5 Dec 2025, 19:45 UTC Feeds2.FeedburnerF5 79% similarity 26.3

Article Content

Browse articles
ThreatCluster

Security researchers at Cato Networks have identified a new attack technique named HashJack, which targets AI browsers and agentic AI systems. This indirect prompt injection method allows attackers to manipulate these systems into delivering phishing links, sharing sensitive data, or providing misleading information. The attack leverages malicious instructions hidden in the #fragment of URLs that appear legitimate.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story