The Containment Era is here. →Explore

Executive Summary

In October 2025, cybersecurity researchers uncovered a significant prompt injection attack targeting Perplexity's Comet AI browser. Dubbed "CometJacking," this incident involved adversaries embedding malicious prompts in links, which—when clicked by users—triggered unauthorized data siphoning through the browser's agentic AI capabilities. Sensitive information, including from connected services like email and calendars, was exposed, demonstrating how AI-driven interfaces can be subverted via crafted input. The attack exploited trust in browser automation and the deep integration of third-party services, raising concerns about the security of AI-powered productivity tools.

This incident is highly relevant as prompt injection attacks are rapidly emerging as a primary risk vector for generative AI environments. The growth in agentic AI and interconnected browser-based workflows has exposed new attack surfaces, prompting urgent calls for improved input validation, isolation of automation agents, and strengthened compliance for AI SaaS applications.

Why This Matters Now

Prompt injection attacks against agentic AI platforms are escalating, exposing a major gap in existing access controls and input validation. As organizations accelerate AI adoption, the risk of data loss and shadow AI activity increases, demanding rapid advancements in AI security and regulatory compliance practices.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attack exploited insufficient input validation and lack of segmentation in agentic AI workflows, highlighting needs for stronger zero trust policies and real-time anomaly detection aligned with NIST 800-53, HIPAA, and PCI controls.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, east-west security, egress controls, and real-time threat detection would have significantly limited the ability of a malicious prompt injection to escalate, move laterally, and exfiltrate sensitive data through the Comet AI browser. CNSF-aligned controls could detect anomalous traffic flows, enforce least-privilege boundaries between browser sessions and cloud workloads, and prevent unauthorized outbound communications.

Initial Compromise

Control: Multicloud Visibility & Control

Mitigation: Early detection of suspicious inbound traffic or anomalous browser requests.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Enforced identity-based least privilege boundaries block unauthorized access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Prevents unauthorized internal traffic between workloads or services.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Anomaly detection flags and interrupts covert command activity.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Outbound data extraction attempts are blocked or logged and alerted.

Impact (Mitigations)

Autonomous policy enforcement confines attack blast radius and enables fast containment.

Impact at a Glance

Affected Business Functions

  • Email Communications
  • Calendar Management
  • Data Storage
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive emails, calendar events, and stored credentials due to unauthorized access facilitated by the prompt injection vulnerability.

Recommended Actions

  • Implement Zero Trust Segmentation to isolate browser workloads from connected cloud services, enforcing least privilege access.
  • Deploy East-West Traffic Security policies to restrict unauthorized lateral movement between SaaS, browser, and backend applications.
  • Enforce rigorous egress controls with FQDN filtering to block shadow AI exfiltration attempts and monitor outbound data flows.
  • Enhance real-time Threat Detection & Anomaly Response to rapidly flag and contain suspicious prompt behaviors and abnormal commands.
  • Centralize Multicloud Visibility & Control to proactively observe, baseline, and audit cloud-deployed AI and SaaS browser interactions.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image