Skip to main content
ukiyo journal - 日本と世界をつなぐ新しいニュースメディア Logo
  • All Articles
  • 🗒️ Register
  • 🔑 Login
    • 日本語
    • 中文
    • Español
    • Français
    • 한국어
    • Deutsch
    • ภาษาไทย
    • हिंदी
Cookie Usage

We use cookies to improve our services and optimize user experience. Privacy Policy and Cookie Policy for more information.

Cookie Settings

You can configure detailed settings for cookie usage.

Essential Cookies

Cookies necessary for basic site functionality. These cannot be disabled.

Analytics Cookies

Cookies used to analyze site usage and improve our services.

Marketing Cookies

Cookies used to display personalized advertisements.

Functional Cookies

Cookies that provide functionality such as user settings and language selection.

Being Deceived on Your Behalf: The True Nature of the "New Attack Surface" Opened by Agent AI: Taking Over AI with Invisible Commands in the "CAPTCHA Era of Fraud"

Being Deceived on Your Behalf: The True Nature of the "New Attack Surface" Opened by Agent AI: Taking Over AI with Invisible Commands in the "CAPTCHA Era of Fraud"

2025年08月22日 01:07
Agent-based AI browsers automate the process from "search to execution." However, a review by Guardio Labs identified instances of AI's unique "unquestioning automation," such as automatic purchases on fake e-commerce sites, automatic navigation to phishing bank sites, and execution of malicious prompts hidden in CAPTCHA-like pages. While Comet may stop under certain conditions, there have been reports of it sending autofilled address and credit card information without user approval, prompting follow-up reports from multiple media outlets. Brave provided a technical explanation of indirect prompt injection and mentioned progress in fixes, but maintained a cautious stance, stating that "complete prevention is not guaranteed." On social media, there is growing criticism of AI's tendency to "automatically mess up," with calls for minimizing execution permissions and stricter human approval. For the time being, users are advised to prohibit the automatic processing of payments and credentials and to verify the legitimacy of URLs through official channels as part of a multi-layered defense strategy.
← Back to Article List

Contact |  Terms of Service |  Privacy Policy |  Cookie Policy |  Cookie Settings

© Copyright ukiyo journal - 日本と世界をつなぐ新しいニュースメディア All rights reserved.