url fragments

  1. HashJack Prompt Injection: URL Fragments Weaponize AI Browser Assistants

    A fresh prompt-injection variant called HashJack has staked out an unexpected and stealthy attack surface: the text that appears after the “#” in a URL — the fragment identifier — can be weaponized to deliver natural‑language instructions to AI-powered browser assistants, tricking them into...