Hackers Can Use GenAI to Change Loaded Clean Page Into Malicious within Seconds
ID: d550d316-47b9-5828-b0cb-5cbd44942dd8
STIX ID: report--d550d316-47b9-5828-b0cb-5cbd44942dd8
Feed Name: cybersecurityNews.com
Security researchers (Unit 42) demonstrated a novel threat where attackers embed hidden prompts in otherwise benign webpages to request malicious JavaScript from public generative-AI APIs (e.g., Google Gemini). The AI is manipulated via prompt engineering to produce polymorphic, runtime-assembled code that executes in the browser to render phishing pages and harvest credentials; because the payload is generated at runtime and requested through legitimate AI domains, traditional signature- and network-based defenses can fail, and researchers recommend runtime behavioral detections in the browser.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
