Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror

Submission + - Perplexity Comet security flaw shows AI browsers are easily hijacked (nerds.xyz)

BrianFagioli writes: Brave researchers have revealed a troubling vulnerability in Perplexityâ(TM)s Comet that shows just how risky AI-powered browsers can be. The flaw, known as an indirect prompt injection, allowed attackers to trick the browser into carrying out hidden commands.

The research was led by Brave engineer Artem Chaikin and detailed with VP of Privacy and Security Shivan Kaul Sahib. They found that Comet could not tell the difference between a userâ(TM)s instructions and malicious text hidden inside a webpage. That oversight opened the door to serious account takeovers and data theft.
In their demonstration, a Reddit comment with invisible text instructed Comet to visit Perplexityâ(TM)s account page, grab the userâ(TM)s email, intercept a one-time password from Gmail, and then send the stolen data back to the attacker. Once the victim clicked âoesummarize page,â the AI did the rest automatically. No additional input was required from the user.

This kind of attack bypasses traditional web safeguards such as same-origin policy and CORS. Those protections normally prevent websites from stealing data across different domains, but when an AI assistant has full control of the browser, the rules break down. Because the AI operates with the full privileges of a logged-in user, it can move freely between services and access sensitive accounts without the user realizing what is happening.

Submission + - Major US Grocery Distributor Warns of Disruption After Cyberattack (techcrunch.com)

An anonymous reader writes: United Natural Foods (UNFI), a major distributor of groceries to Whole Foods and other retailers, said on Monday that it was hit by a cyberattack, warning of disruptions to its ability to fulfill and distribute customer orders. UNFI said in a Monday filing with the U.S. Securities and Exchange Commission that it became aware of unauthorized access to its IT systems last Thursday, and began shutting down portions of its network. The filing added that the company has “implemented workarounds for certain operations in order to continue servicing its customers where possible,” but noted that the intrusion has caused ongoing disruptions to its business operations.

The Providence, Rhode Island-based company is one of the largest grocery distributors in North America, selling fresh produce, goods, and food products to more than 30,000 stores and supermarket locations across the U.S. and Canada. UNFI also serves as the “primary distributor” to Whole Foods, the Amazon-owned grocery chain. Last year, the two companies extended their long-running contract until May 2032.

Submission + - SPAM: Google AI-driven products to replace robots.txt

terrorubic writes: As new technologies emerge, they present opportunities for the web community to evolve standards and protocols that support the web’s future development. One such community-developed web standard, robots.txt, was created nearly 30 years ago and has proven to be a simple and transparent way for web publishers to control how search engines crawl their content. We believe it’s time for the web and AI communities to explore additional machine-readable means for web publisher choice and control for emerging AI and research use cases.
Link to Original Source

Comment Amyloid Cascade Hypothesis Antigen (Score 1) 29

This new drug promises to be a great weapon against the Amyloid Cascade hypothesis. Itâ(TM)s a shame it likely wonâ(TM)t be as effective against Alzheimerâ(TM)s Disease. The timing is unfortunate: we have known for a while now that even the most potent Beta Amyloid clearing drugs have only a marginal impact at best. But while the leading edge of research searches for other mechanisms, we donâ(TM)t have anything thatâ(TM)s more effective, either. https://bigthink.com/neuropsyc...

Submission + - NASA kills its X-57 electric plane before it ever flies (popsci.com) 1

schwit1 writes: NASA said today in a conference call with reporters that it would not ever be flying its experimental electric aircraft, the X-57, citing safety concerns that are insurmountable with the time and budget they have for the project. The X-57 program will wind down without the aircraft ever going up into the sky.

The project had previously seen challenges. For example, transistor modules in the electrical inverters kept failing and “blowing up” in testing, Sean Clark, the project’s principal investigator told Popular Science in January. That problem was solved, Clark said.

The problem that led them to scrap the plan to fly the aircraft stemmed from motors that power the propellers. Clark said today that analysis of the issue is ongoing. “As we got into the detailed analysis and airworthiness assessment of the motors themselves, we found that there were some potential failure modes with the motors mechanically, under flight loads, that we hadn’t seen on the ground,” he said. “We’ve got a great design in progress to fix it, it’s just [that] it would take too long for us to go through and implement that.”

NASA said that the reason behind permanently scrubbing the flight is safety and time. “Unfortunately, we recently discovered a potential failure mode in the propulsion system that we determined to pose an unacceptable risk to the pilot’s safety, and the safety of personnel on the ground, during ground tests,” Bradley Flick, the director of NASA’s Armstrong Flight Research Center in California, said in the call. “Mitigation of that failure would take the project well beyond its planned end at the end of this fiscal year, so NASA has decided to end the project on time without taking the vehicle to flight.”

Comment Re:This is... (Score 1) 674

Old hat. Even the 20% economy improvement has been ripped off prior scam-device claims of similar variety.

The entire class of vaporization enhancement devices has been thoroughly done away with: http://www.fuelsaving.info/atomisation.htm

A device using an electric field to affect gasoline vaporization is particularly dubious: gasoline being a non-polar fluid, it is entirely unaffected by electric fields.

Slashdot Top Deals

Logic is a systematic method of coming to the wrong conclusion with confidence.

Working...