Threat · curated 30 Jun 2026
New BioShocking attack manipulates AI browser into data theft
First reported huntress.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Framing malicious actions as fiction can defeat AI browser guardrails, turning autonomous browsing agents into a data-exfiltration vector.
A new prompt injection attack dubbed 'BioShocking' reportedly tricks AI-powered browsers into treating risky real-world actions as part of a fictional scenario, bypassing safety guardrails and enabling data theft.