Researchers have identified security vulnerabilities in Amazon Bedrock, LangSmith, and SGLang that could enable data exfiltration, account takeover, and remote code execution in AI environments.
GhostPoster malware used 17 Mozilla Firefox add-ons to execute affiliate link hijacking, ad fraud, tracking injection, and remote code execution, affecting over 50,000 users.
Researchers uncover that Urban VPN browser extension silently collected AI chatbot prompts and responses from millions of users across ChatGPT, Claude, Copilot, Gemini, and other platforms.