Having an AI browser that does things for you sounds good. Until a hacker uses it to steal all your money

Ask the AI ​​to make a summary of that article that you just saw in Reddit can be very expensive. It is what They just revealed Those responsible for Brave, who have discovered a surprisingly simple way to hack the browser of the perplexity comet to do not only what the user asks, but what an attacker has managed to convince him to do. The danger of leaving everything in the hands of AI is evident. What happened. Brave’s experts, a browser that competes with Chrome or Firefox and also has AI functions, wanted to analyze the risk of using an agetic browser like the one It offers perplexity right now with Comet. And what if they have done it. The browsers with ia promise a lot. Thanks to tools like Comet – Openai too has its chatgpt agentheir of Operator-, It is possible that the browser becomes a kind of digital butler and do things for us autonomously when visiting websites. Thus, you can summarize a news, tell you which song appears in that YouTube video, look for offers, answer emails or complete purchase processes. A priori the advantages are huge, but be careful, because there are also important risks. But be careful to let go of the steering wheel. However, delegating everything in the browser can raise a real threat to the safety and privacy of our data. If we trust them too much, these browsers may have access to all our data, since theoretically they will benefit from access to our email, but also to banking and financial data and even health. What happens if the amazing model or makes mistakes? Or worse: What happens if someone modifies the content in a malicious and invisible way for ia agents to follow malicious instructions? Having the AI. That is just what They discovered in Brave When trying a simple technique. They published a malicious comment on a Reddit thread, and then asked Comet to summarize the article. When they went to do it they verified how Comet did not know whether the content of that thread could or not contain malicious instructions: he simply met them and followed them. And in thread, as can be seen in the video, there were some simple instructions that stole the credentials of their perplexity account and even intercepted the verification code that the platform sent to the user to log in the service. Result: Automatic account by the attacker thanks to the AI. How the attack works. As Brave experts explain, the problem is that the way of hacking this type of browse is not hacking the browsers, but hacking the content, something that is very, very simple. The steps are the following: Configuration: An attack writes Malicious instructions in some content on the web. If you control that site, you can hide instructions using blank text if the background is also white, or in comments or other invisible elements. They can also do it directly “injecting” those instructions through comments in publications on social networks such as Reddit or Facebook. Activation: A user sails to that website and uses the browser with AI. If you do something simple as “Summarize this page“Or ask that certain information be extracted, these malicious instructions are activated. Injection: As the AI ​​processes the information on the page, see those malicious instructions and follow them. It is not able to distinguish whether the content has a malicious purpose or not, and considers everything as part of what you should do at the request of the user. Exploitation: these malicious commands and instructions indicate to the navigator’s tools to perform various actions, such as navigating the user’s bank account, Extract stored passwords In the browser or collect information to a remote server controlled by the attacker. Possible solutions. Those responsible for the study indicate that to protect themselves from these types of problems, agricultural browsers must first differentiate between what the user has asked for and what the user content is. The content of a website “should always be treated as non -reliable.” In addition, the browser with AI should necessarily ask for the user’s interaction to perform certain actions, how to access passwords or perhaps send an email. Restrict permissions to the agetic browser and make good use of Two -step verification systems “With mobile applications such as Google Authenticator, for example,” are also adequate ways to mitigate a problem that can put in many problems the deployment of these tools. Outstanding image | Perplexity, Xataka with mockuuups studio In Xataka | I have tried day, the browser that replaces ARC and bets everything to AI. It hasn’t come out as expected

How it works and how to avoid this method to steal mobiles in summer

Summer arrives, and with the new baking of methods that criminals use to steal. In this case Let’s explain the trap of the false tourist and google mapsa type of thymus that is being seen in cities like Benidorm, and for which it is convenient to be prevented. We are going to start the article explaining the mechanics and the procedure of this deception with which thieves can try to steal your mobile phone. Then we will give you A series of tips To prevent this robbery and to avoid that if they manage to steal your mobile, you can make many misdeeds. How this scam The way of proceeding of thieves is so simple that it is difficult not to fall into the trap. To begin with, a stranger for the street getting through a disoriented tourist That is looking for your hotel. Here, it is normal for us to stop helping. This supposed tourist Ask you to look for your hotel on Google Maps in order to know how to get to him. Then you take out the mobile, unlock it and start looking on Google Maps. That is, just when you unlock the mobile the thief takes ittake it from the hands of a pull and run with the device. The biggest problem of this trick is that The thief takes your mobile already unlockedso you can access your photos, your conversations at WhatsApp or your documents. You can access sensitive information and even impersonate you in WhatsApp chats to ask for things or money from your acquaintances. How to avoid falling into the trap Unfortunately, these types of traps and tricks to steal mobile They are difficult to detectsince they play with our mood to encourage others. The most important thing is be aware that you don’t know the other person and take a series of precautions. The first thing is try verbally Any unknown person instead of quickly getting the mobile. And if there is no choice but to do it, then have well subject the device While you proceed. Pay attention to the movements of the other person, and always try to have two hands on him and have him grabbed hard. Do not trust yourself. There are also A series of precautions to take when you are travelingsince in a tourist city there are more possibilities that there are attempts to rob. For example, Activate additional block for sensitive appsputting an extra layer as a trace block, recognition or even Pin to apps such as the bank, your photos or whatsapp and social networks. Come on, in addition to screen blocking, you activate a specific blockade for apps, something you can do on both Android and iOS. It can be annoying when using them daily, but will save your data if someone steals your mobile already unlocked. Have active mobile location systems to know where you are stealing, and try the mechanisms to block it remote or turn it off so that thieves cannot use it. For this, access from another device will be needed, so you have the family systems configured to be able to block it from the mobile of a spouse or family. In Xataka Basics | Broken rearview scam: how it works and how to avoid the scam in which they hit your car and leave you a note to cheat and steal

They are the players who steal their iconic towels. And with impudence

Wimbledon is tradition. The British tournament that started in 1877 has become one of the great events of world sport and this year introduced a technological novelty: replace line judges for an AI. It is a change that has already brought controversybut there is something that does not change is that players love to steal Wimbledon towels. So much that it has gone from being a headache for the tournament with simple resignation. And the funniest thing is that players have no qualms about detailing their ‘tricks’ to get the coveted loot. Specials? We might think that a towel is nothing with the more than 53 million pounds that are They will distribute This year during the competition, with three million only for the individual and female individual winners. But the towels, protagonists of fights in the stands, are also part of that loot that players want. The two designs this year They are “normal” towels. Manufactured by the British company Christy for 38 years, they measure 133 x 70 centimeters, weigh 500 grams and are made completely cotton. The male towels are always the same, with the “butter” letters and a purple and green design. The female were changing every season (although recently That is over and everyone receives the same) and a cult has been aroused around these towels, which even They announce His designs before tournaments. Bite in towels. As each element of a sport, especially if used by the star you have gone to see, a towel can become a Collection objectlike a ball or a doll. However, we are not talking about the towels being popular only among fans: the real problem of the tournament is with the players. How far? As we read in The Timesthe tournament had about 7,000 towels in stock this year with a single purpose: that they were a tool for players. Until last Thursday, when only the first rounds of the competition had been played, they had already distributed 2,799 towels. The players know that they must return them (not mandatory, but they will be asked for) before going to the locker room at the end of the game, and the All England Club – those responsible for the event – usually do it, but of those 2,799 distributed, only 828 returned to where they should. Modus operandi. The question is how they do it with all the cameras pointing and knowing that the theft of towels is A controversy Internal that the tournament has been dragging for years. The short answer is that the big stars, directly, do not care that the cameras point them. In fact, some tell how several dozens of towels get during their career. At the beginning of the game, each player receives two towels and, if the games lengthen and sweat more, or if it begins to rain, they can ask for an additional chair judge. They are extremely conservative numbers of the tournament because reality is very different. As we read in BBCDjokovic is one of those proper names. He says that, as soon as the game begins, one gets into the racket bag. And, in the middle of the meeting, ask for another due to sweat. Another way is that of Tracy Austin, who said he takes advantage of the rain stops to get some extra and that he usually ends four at the end of the game. So that? For what you are thinking: give it away To friends and family because, as Austin said, it is not enough to buy one of the memories store (they sell the same for 60 euros and that also sells your own Christy Online), it must be the authentic players. And there is no request for requests because it depends on the chair judge and it would be rare for him to refuse. In the end, the one that they use most is that towel with ice inside The big blow. Here are those who have more or less great collections. Djokovic has a good trousseau to give away and Serena Williams also commented on BBC that has towels since 1997 of both women and men. Rafa Nadal is another of the players that each game can end a good booty of towels. The amount of sweat depends on each person and there are times when even We have seen Nadal loading with a garbage bag full of these objects. According to the Official numbersare returned between 15% and 20% of the towels each championship and, although Wimbledon not short of funds, it is estimated that this habit of the players generates losses of $ 160,000. With the greats it is a “joke.” With the “little” no. It seems that the All England Club does not put too much effort to recover the towels of the stars, but in Wimbledon there are also minors who are emerging and there they have taken measures. If you have seen a Wimbledon game in which a white towel is distributed, it is because it is one of the destined to the Junior tournaments and the tennis players invited by the championship. They are given a Wimbledon officer of that year, but the second is white, without any distinctive and, of course, much less glamorous because if you give it to Wimbledon or anywhere else. Resignation. What All England Club is clear is that they will not be chasing anyone. They already ask for the towels back educated, but in this year’s edition, Winston Sedgwick, of the logistics team of the event, said in The Times that players know perfectly that they give towels and that there is no limit. “We used to expect them to return them, that’s why we asked them to try to recover them, but that will no longer be done.” “It’s like when you’re going on vacation and you bring back a souvenir home,” says Sedgwick with resignation. And what I am clear is that I am going to look much … Read more

Israel is not only attacking Iran with missiles. He also just steal 90 million dollars in cryptocurrencies

It is not much less cryptocurrency theft more large in historybut those 90 million dollars are especially significant for whom they are involved and why. Those involved They are Israel and Iran. And why, unfortunately, The war that they maintain both nations. Israel hacking to Iran. The war between Israel and Iran is intensified, and does not only New and striking tactics On the battlefield. It also does it through cyber warmen. A group called Gonjeshke Darande, (predatory sparrow, in a translation from the Persian) Hackeo has been attributed of the Iranian market of Cryptodivisas Nobitex. Possible link to Israel. There is no definitive evidence of a direct link between the Government of Israel and this grip hacker, Sophos experts indicate. Rafe Pilling, Director of Intelligence of Threats in that firm, explained that the cyber attack had all the characteristics of an attack supported by a government. 90? Millions of dollars. The Hacker Group has achieved according to The Guardian steal 90 million dollars, although the page of the Wikipedia Persian edition It indicates that the robbery amounted to 3.76 billion rials, about 47 million dollars, although that money may be stolen from one of the two troonscan wallets destination From Gonjeshke Darende they have also threatened to publish both the company’s internea information and the source code of its cryptodivsis purchase platform. The final amount is not entirely clear, and According to Cointegraph It is exceeding 81.7 million dollars. Cold purses, safe. The attack, They support Nobitexhas allowed to steal the cryptocurrencies of the “hot” purses of the platform, used to facilitate daily transactions. He has not affected cold, safer purses. Nubitex blocked access to the platform as soon as they and those responsible say that “all damages will be compensated through the insurance fund.” In a later message They have revealed that the impact of the attack is “more complex than it was initially estimated.” And above, Internet cuts. From Nobitex they explain that their capacity to respond to cyber attack has also been affected by the cuts in the country’s internet infrastructure, “together with limited access to the facilities due to the current national crisis.” They hope to recover and restore their services in the next 4 or 5 days, but in the meantime the platform is still unable to be accessed. A hacking with political motivation.Yehor Rudytsia, security researcher at the Hacken firm, said in Cintelegraph how this cyber attack is more “a political statement than a robbery with economic motivation.” In fact, according to The Guardian the hackers have “burned” those funds storing them in custom addresses (“Vanity Addresses“) that they do not have a known private password or possibility of recovering. For example, a purse such as” 0x0000000000000000000000000000000000000000000000 Transferring cryptocurrencies to this type of addresses is actually destroying them voluntarily by leaving them blocked forever. The hackers have used directions with variations of the term “Jo *** Osterrorists”. Image | Wikipedia | Art Rachen In Xataka | Iran and Israel are starting another war in the background: that of the false images created with AI

The Supreme Court has just resolved who is responsible when you steal all your money for Phishing: the bank

The Supreme Court has just failed in favor of users and against banking in one of the most recurrent issues in recent years: Scams through the Internet. He declares that banking is the main responsible in these cases of fraud, being forced to immediately replenish all money stolen from the client. It is not a user thing. The Supreme Court has confirmed A sentence issued on April 9in which the Civil Chamber rejected the appeal filed by Ibercaja against a resolution issued by the Provincial Court of Zaragoza in November 2022. In this sentence 571/2025 it is underlined that good banking practices require the activation of systems capable of detecting suspicious activities, as well as blocking or verifying high -risk operations. Almost 60,000 euros, back to pocket. Unless it can be demonstrated that the client acted negligently, the bank is obliged to assume responsibility and return the money immediately. In this case, Ibercaja Banco SA must reintegrate a client 56,474.63 euros stolen from his account through Sim Swappinga system to supplant our identity stealing the telephone number. Judge Manuel Almenar Belenguer uses the European Directive before payment servicesas well as the Spanish regulations, concluding that if there is no negligence, the user’s only obligation is to notify the bank about any type of unauthorized operation. The new jurisprudence. This case feels a fundamental precedent since it establishes that, from now on, the banking entities will be the main responsible in cases of Phishing banking. Consequently, they must respond for user -unauthorized operations, thus marking a significant change in customer protection against electronic fraud. “The advances of current technology make relatively easy to design ideal computer systems or applications to detect certain anomalies in the provision of payment services. Operations that, in the case of companies or companies with a concrete corporate purpose, can be described as ordinary, must immediately raise suspicions and give rise to an answer when they affect natural persons outside of such activity.” Banks will no longer have an excuse. Based on Judisprudence, it is stated that contractual clauses that exempt the banking entities of their responsibility with users regarding unauthorized operations must be declared knots. Until now, banks could hide in alleged bad practices carried out by the user, such as having introduced their data on websites or malicious links. After this sentence, they are responsible for any unauthorized operation. A plague with which the government tries to end. Scams per call and SMS are a plague. So much, that the Ministry of Digital Transformation It has been trying to put a brake over a year. He End of commercial calls It arrived in February 2025 under ministerial order, but this is just a tiny part in the cybethaf cake. False calls, Scams by WhatsApp, malware in stores like Google Play, Identity Supplant by SMS… tactics change and evolve to continue having an affectation and result. Recently, The Civil Guard dismantled a network of cybers allegedly led by a 19 -year -old student. User’s responsibility. Despite the additional protection that the clients of the entities will enjoy in case of cybetafa, it falls on the roof of the user not to fall into practices that can end up being considered as negligence. These have not established themselves, but it is worth not introducing our phone, personal email on the websites whose origin we are not clear. In case of using Android, we are also responsible for what we download and where we download it, as well as the permits that we give to the applications. Protecting goes beyond possible money subtractions: it is especially easy to end up giving all our data to cybers. In Xataka | Cybethafa with Word documents as a Trojan horse: how it works and how to protect your personal and financial data

There is a person who knows more than anyone in the world about password robberies. And they just steal his

Troy hunt It has been for years warning us of the dangers of the passwords. It happened so often that it ended up turning those warnings In a project that has become a reference: Have I Been Pwned. And despite everything he knows, he has just fallen into a theft of credentials with the most common method of all: A Phishing email. Can happen to anyone. Hunt had in his blog how it fell into a very well elaborate trap: a phishing email that pretended to come from Mailchimpthe platform you use to distribute your newsletter. In the notice he was informed that he had received a spam complaint and that his shipping privileges in the service would be restricted. To solve it, yes, I could click on a button with a link. Why did that phishing work? As this expert explained, “I have received a ton of similar messages that I have always identified quickly”, but there was a critical factor that played against him: the moment in which he received it and read it. Hunt had Jet Lag and was very tired when he received the message, and did not think enough that something was not right. Difficult indications to identify. After clicking on the link, Hunt also noticed how his password manager did not autocomplete the details of his account (user and passwords, usually). This could have been an indication that the domain from which those credentials were requested was suspicious, but he himself indicated that many platforms record you in a domain (which the password manager keeps) and then authenticate you in another. Theft of their subscribers. Phishing’s attack caused the attackers to steal 16,000 records that belong to people who subscribed but also that he had already discharged from his Newsletter. Mailchimp keeps those registers for some reason. In these data, email, IPS and latitude and length addresses are included, however they do not point to the subscriber location. He has also been “Pwned”. The creator of the Have Ien Pwned site ended up adding the theft of his data to the database he uses on this platform, as was of rigor. As he pointed out in his blog, not to do it “it would have been a hypocrisy.” He also had the success of telling what had happened to him right away. If a message is super urgent, suspect. Phishing attacks usually always take advantage of being written with an urgency tone or message. If you don’t act, they try to tell you, something bad can happen to you. That is precisely why in these messages it is to try to keep the head cold and clear and not act instinctively or immediately. It is probably the great lesson that can be taken from this event. Passkeys help. Traditional passwords remain a potential threat to phishing attacks, but there is a method that helps us avoid that threat in particular: Passkeys or Paso Keyswhich make use of safe biometry. Its implementation, yes, is quite fragmentedbut we deposit confidence in a passkeys provider (such as Google either Applefor example) are undoubtedly An important element To add a remarkable safety layer, as well as the authentications in two steps (2FA) have been so far. Image | Saksham Choudhary In Xataka | There are users who pass from passwords. And they go to “I forgot my password” to generate them again and again

They are being used to cheat and steal information

Surely this situation is familiar: You have a PDF file and you need to turn it into .doc To edit it in Word. An option would be to pay the Premium version of Adobe Acrobat, which allows you to do it, but most likely we seek to “convert PDF to Word” into Google, we access an online tool and upload the PDF without the slightest prevention. Well, this action, so innocent in appearance, can end up regular, as they have warned from the FBI. What happened. The FBI office in Denver has issued an official statement in which they claim that their agents “are increasingly detecting Related scams With free online document conversion tools. “The modus operandi is relatively simple:” criminals use free tools for online document conversion to load malware in victims computers, giving rise to incidents such as ransomware. “ How do they. From the agency they explain that cyberdelicuents are using free conversion or unloading tools. Although they do not give concrete names, they do notice that the attack vector can be a website that promises to convert a PDF to Word or Combine several images in PDFor a tool to download videos and/or convert MP4 into MP3. It is easy to imagine examples of these tools. They work, but they go with a bug. These tools can work and comply with what is promised, but nothing guarantees that the returned file is not infected. PDFs can contain malwaresuch as a JavaScript code that exploits vulnerability or sets a process through commands on our PC. An MP3 can also be infected, although not infecting itself, but exploiting vulnerability in a player, for example. That is, the options are varied. In an online file converter you have to take into account which files returns us and what we do with those we have uploaded Who is looking at. Beyond returning an infected file, these tools can obtain valuable information from us another way: seeing the files we have uploaded. If we have uploaded a PDF with our mail and telephone number (we think of a CV), it is possible that whoever is behind the malicious website uses this information for little lawful purposes. Let’s not talk about bank information, passwords, photos in which we leave, etc. The importance of going with an eye. It should be noted that not all online tools are malicious, much less. That a website has a privacy policy where they clearly explain what they do with your files, contact information and that is known is already a good indicative. When in doubt, it is always a good idea to pass the files generated by a platform as Virustotal. Cover image | NaO Triponez and Markus Spiske edited by Xataka In Xataka | If you use cable headphones, you are vulnerable: they are a caramel for hackers

Log In

Forgot password?

Forgot password?

Enter your account data and we will send you a link to reset your password.

Your password reset link appears to be invalid or expired.

Log in

Privacy Policy

Add to Collection

No Collections

Here you'll find all collections you've created before.