Close Menu
TechUpdateAlert

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Tribit Stormbox Mini Plus review: an budget Bluetooth speaker that does the basics but sadly lacks sonic oomph

    August 9, 2025

    Honor 400 Smart 5G Design, Specifications Surface on Telecom Operator’s Site Ahead of Imminent Debut

    August 9, 2025

    Sony CFO Calls Xperia Brand ‘Very Important’ Part of Business Amidst Ongoing Challenges

    August 9, 2025
    Facebook X (Twitter) Instagram
    Trending
    • Tribit Stormbox Mini Plus review: an budget Bluetooth speaker that does the basics but sadly lacks sonic oomph
    • Honor 400 Smart 5G Design, Specifications Surface on Telecom Operator’s Site Ahead of Imminent Debut
    • Sony CFO Calls Xperia Brand ‘Very Important’ Part of Business Amidst Ongoing Challenges
    • How Strength Training Can Help You Burn Fat, No Treadmill Required
    • Deals: Galaxy Z Flip7 and Z Flip7 FE get cheaper Buy and Try offers, Z Fold7 paired with Buds3 Pro
    • Realme 15 Pro Game of Thrones Limited Edition Variant Can Reportedly Launch Soon
    • Mini Ikea stores will be opening inside some Best Buys this year
    • What Even Is Instagram Now?
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechUpdateAlertTechUpdateAlert
    • Home
    • Gaming
    • Laptops
    • Mobile
    • Software
    • Reviews
    • AI & Tech
    • Gadgets
    • How-To
    TechUpdateAlert
    Home»AI & Tech»Researcher finds Microsoft’s agentic HTML can leak passwords, AI keys
    AI & Tech

    Researcher finds Microsoft’s agentic HTML can leak passwords, AI keys

    techupdateadminBy techupdateadminAugust 6, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    AI PC art
    Share
    Facebook Twitter LinkedIn Pinterest Email

    With new AI systems comes new AI vulnerabilities, and a big one was just discovered. It’s a flaw in Microsoft’s method of allowing agents to interact with websites on your behalf.

    Microsoft calls this technique NLWeb, which is a kind of HTML for AI agents. The company unveiled this at its Build conference this spring, and has since leaned into that vision with an experimental Copilot Mode for its Edge browser. (Microsoft hasn’t confirmed whether it uses NLWeb for this.)

    Researcher Aonan Guan, however, has discovered a vulnerability in NLWeb: a path traversal bug that lets any remote user read sensitive files like system configurations and cloud credentials via a malformed URL.

    In a Medium post, Guan showed how he was able to download a list of the system passwords along with Google Gemini and OpenAI keys. This would let an attacker run additional server-dependent AI applications “for free,” without being charged by OpenAI.

    According to Guan, Microsoft’s Security Response Center pushed a patch to the GitHub repository in June, confirming the problem was fixed. Microsoft hasn’t issued an official patch report. Users, however, don’t need to take any actions.

    It’s fair to say that AI development has proceeded at breakneck speed. But, as Guan points out, the line between chatting with an AI and issuing it commands can blur.

    “The very nature of NLWeb is to interpret natural language,” Guan said. “This blurs the line between user input and system commands. Future attack vectors could involve crafting sentences that, when parsed by an agent, translate into malicious file paths or actions.”

    We’ve already seen ChatGPT interactions leak out into Google’s search results. (ChatGPT has now reportedly turned off the flag that makes ChatGPT chats discoverable.) As Guan (and The Verge, which reported the story) note, leaks of such magnitude in an AI agent can be catastrophic for all involved.

    Agentic finds HTML keys leak Microsofts passwords Researcher
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHow to Season a Griddle and Keep It From Rusting
    Next Article 5 new Prime Video movies with over 90% on Rotten Tomatoes I recommend streaming in August 2025
    techupdateadmin
    • Website

    Related Posts

    AI & Tech

    Sony CFO Calls Xperia Brand ‘Very Important’ Part of Business Amidst Ongoing Challenges

    August 9, 2025
    AI & Tech

    Don’t break the bank on your next tablet. This Android one is less than $70

    August 9, 2025
    AI & Tech

    “Speed is everything” – how Arm and Aston Martin’s new wind tunnel venture looks to bring in a new era of success

    August 9, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Apple Pencil With ‘Trackball’ Tip, Ability to Draw on Any Surface Described in Patent Document

    July 9, 20253 Views

    Samsung Galaxy Z Fold 7 and Galaxy Z Flip 7: First Impressions

    July 9, 20253 Views

    The Bezos-funded climate satellite is lost in space

    July 9, 20252 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Best Fitbit fitness trackers and watches in 2025

    July 9, 20250 Views

    There are still 200+ Prime Day 2025 deals you can get

    July 9, 20250 Views

    The best earbuds we’ve tested for 2025

    July 9, 20250 Views
    Our Picks

    Tribit Stormbox Mini Plus review: an budget Bluetooth speaker that does the basics but sadly lacks sonic oomph

    August 9, 2025

    Honor 400 Smart 5G Design, Specifications Surface on Telecom Operator’s Site Ahead of Imminent Debut

    August 9, 2025

    Sony CFO Calls Xperia Brand ‘Very Important’ Part of Business Amidst Ongoing Challenges

    August 9, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2025 techupdatealert. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.