Michael Bargury, CTO of Zenity, revealed that enterprise AI agents are highly susceptible to zero-click attacks, which exploit their gullibility. These attacks can manipulate AI systems like Cursor, Salesforce, and…
Perplexity has responded to claims regarding a vulnerability in the Comet browser, asserting that allegations of remote code execution (RCE) are 'fake news.' Despite this, researchers have indicated that the Comet…
Zenity Labs disclosed a family of critical vulnerabilities known as PleaseFix, affecting agentic browsers including Perplexity Comet. These vulnerabilities enable zero-click agent hijacking, local file exfiltration, and…
SquareX has revealed a hidden MCP API in the Comet AI browser that allows extensions to execute arbitrary commands on users' devices. This API bypasses security measures found in traditional browsers, posing risks to…
Perplexity has responded to claims regarding a vulnerability in the Comet browser, which researchers allege can be exploited to execute local commands. Despite evidence of a silent patch, Perplexity labels the…
SquareX claims to have identified a method to exploit a hidden Comet API for executing local commands. Perplexity disputes this assertion, labeling the research as fake. The disagreement highlights ongoing tensions in…
SquareX has reported that significant vulnerabilities in popular web browsers pose a major risk to enterprises. Their Year of Browser Bugs program revealed serious flaws in browser extensions, AI-driven browsers, and…
A vulnerability in the obscure MCP API of the Comet Browser has been identified, allowing potential attackers to gain full control over user devices. This breach compromises user trust and highlights significant…
SquareX claims to have discovered a vulnerability in the Comet browser that allows for the abuse of a hidden API to execute local commands. Perplexity disputes this claim, labeling the research as fake. The disagreement…