As AI platforms become part of daily workflows, attackers have found a new way in: the platforms themselves. The Huntress Security Operations Center (SOC) says the bigger day-to-day risk comes from threat actors abusing the AI features people already trust and rely on, rather than attacks on the AI companies or models themselves.

Over the past nine months, Huntress has tracked incidents in which attackers weaponized shareable AI content, public mini-apps, and sponsored search placement to target AI users and deliver malware.

Legitimate features, hijacked

Huntress has observed threat actors abuse a handful of real AI platform features, including:

Claude Artifacts: content Claude generates and displays in a chat preview pane, which users can publish and share via a public link.