New cyberattack reveals vulnerability in AI security analysis

A recent cyber attack has highlighted a structural disconnection between the HTML text and what users actually see in their browsers, allowing attackers to send malicious instructions that go unnoticed by artificial intelligence assistants. This finding was presented by LayerX, a cybersecurity company, which demonstrated its technique through a fake fanfiction site for Bioshock. By using a custom font, the attackers were able to hide a malicious message in seemingly harmless content. Hidden threats in HTML The attack revealed that, although AI assistants like ChatGPT and Claude were examining the […]

A recent cyber attack has highlighted a structural disconnection between the HTML text and what users actually see in their browsers, allowing attackers to send malicious instructions that go unnoticed by artificial intelligence assistants. This finding was presented by LayerX, a cybersecurity company, which demonstrated its technique using a fake Bioshock fanfiction site. By using a custom font, the attackers were able to hide a malicious message in seemingly harmless content.

Hidden Threats in HTML

The attack revealed that, although AI assistants like ChatGPT and Claude were examining the underlying HTML for threats, they lacked the ability to identify hidden content that appeared safe at first glance. In this case, the malicious text urged users to execute a reverse shell on their machines, while the visible text was a set of unreadable characters.

LayerX has pointed out that this vulnerability does not require the use of JavaScript or exploit kits, revealing a flaw in how AI tools analyze the security of web pages. While browsers present information in a designed manner, AIs treat the text of the DOM as the complete representation of what is shown to the user, leaving a gap that attackers can exploit.

In response to this threat, LayerX recommends that AI providers implement dual rendering analysis and treat custom fonts as potential threat surfaces. Additionally, it is vital that these tools avoid making security judgments without having verified the full context of the page. So far, Microsoft has stood out as the only provider that has fully addressed the issue following LayerX’s responsible disclosure in December 2025.

Claude 2 by Anthropic: A Game-Changer in AI with Enhanced Functionality

2023 is shaping up to be the year of Artificial Intelligence in the world of technology. Several companies are currently making significant advancements in this field. One of them is Anthropic, which has just launched the Claude 2 system, packed with improvements compared to its previous version.

While Anthropic may not be as widely known as Open AI or Google in AI research, they are still highly relevant. Claude is their operational AI and has impressive capabilities to process not only dialogue and internet information but also texts and documents provided to it. And now, Claude 2, their enhanced version, is available in Beta phase.

Highlights of Anthropic’s Claude 2

Within Claude 2, significant advancements can be found in text and document processing. This new version allows for the simultaneous analysis of up to five documents and is capable of processing texts with up to 100,000 tokens, a considerable figure that gives it substantial AI muscle.

Claude 2 also boasts improvements in performance and response time, enabling it to work at a faster pace. It also significantly enhances its reasoning abilities and is capable of providing longer and more detailed responses. The only drawback is that it is currently in the Beta phase and available only to users in the United States and the United Kingdom.

Conversational AI is becoming increasingly intelligent and advanced.

Artificial Intelligence in more businesses

Within the Artificial Intelligence industry, we also find more developments, such as the inclusion of GPT-4 in ChatGPT for premium subscribers. Additionally, there is the imminent arrival of Bard in the European Union once they adapt their service to comply with the privacy policies of our region.

ChatGPT DOWNLOAD

Indeed, all these technological advancements are fascinating. However, the legislative frameworks progress much more slowly than these technologies and continue to raise controversies regarding the potentially harmful uses they may entail. We are also witnessing a decrease in usage in tools like ChatGPT, which could lead to a scenario where the bubble around AI bursts in the face of a hypothetical popularity collapse.