A new font-rendering attack causes AI assistants to miss malicious commands shown on webpages by hiding them in seemingly harmless HTML.
Threat actors are publishing clean extensions that later update to depend on hidden payload packages, bypassing marketplace ...