{"id":14021,"date":"2025-12-01T23:48:04","date_gmt":"2025-12-01T20:48:04","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=14021"},"modified":"2025-12-01T23:48:04","modified_gmt":"2025-12-01T20:48:04","slug":"ai-sidebar-spoofing-atlas-comet","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/ai-sidebar-spoofing-atlas-comet\/14021\/","title":{"rendered":"Yapay zeka kenar \u00e7ubu\u011fu aldatmacas\u0131: Yapay zeka taray\u0131c\u0131lar\u0131na y\u00f6nelik yeni bir sald\u0131r\u0131"},"content":{"rendered":"<p>Siber g\u00fcvenlik ara\u015ft\u0131rmac\u0131lar\u0131, yapay zeka taray\u0131c\u0131lar\u0131n\u0131 hedef alan ve yapay <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/spoofed-ai-sidebars-can-trick-atlas-comet-users-into-dangerous-actions\/\" target=\"_blank\" rel=\"noopener nofollow\">zeka kenar \u00e7ubu\u011fu aldatmacas\u0131<\/a> olarak adland\u0131rd\u0131klar\u0131 yeni bir sald\u0131r\u0131 y\u00f6ntemini ortaya \u00e7\u0131kard\u0131lar. Bu sald\u0131r\u0131, kullan\u0131c\u0131lar\u0131n yapay zekadan ald\u0131klar\u0131 talimatlara k\u00f6r\u00fc k\u00f6r\u00fcne g\u00fcvenme al\u0131\u015fkanl\u0131klar\u0131n\u0131n giderek artmas\u0131n\u0131 istismar etmektedir. Ara\u015ft\u0131rmac\u0131lar; Perplexity taraf\u0131ndan geli\u015ftirilen Comet ve OpenAI taraf\u0131ndan geli\u015ftirilen Atlas olmak \u00fczere iki pop\u00fcler yapay zeka taray\u0131c\u0131ya kar\u015f\u0131 yapay zeka kenar \u00e7ubu\u011fu sahtecili\u011fini ba\u015far\u0131yla uygulad\u0131lar.<\/p>\n<p>Ara\u015ft\u0131rmac\u0131lar ba\u015flang\u0131\u00e7ta deneyleri i\u00e7in Comet\u2019i kulland\u0131lar, ancak daha sonra sald\u0131r\u0131n\u0131n Atlas taray\u0131c\u0131s\u0131nda da uygulanabilir oldu\u011funu do\u011frulad\u0131lar. Bu yaz\u0131da, yapay zeka kenar \u00e7ubu\u011fu sahtecili\u011finin i\u015fleyi\u015fini a\u00e7\u0131klamak i\u00e7in Comet \u00f6rne\u011fi kullan\u0131lmaktad\u0131r, ancak okuyucular\u0131n a\u015fa\u011f\u0131da belirtilen her \u015feyin Atlas i\u00e7in de ge\u00e7erli oldu\u011funu unutmamalar\u0131n\u0131 rica ederiz.<\/p>\n<h2>Yapay zeka taray\u0131c\u0131lar nas\u0131l \u00e7al\u0131\u015f\u0131r?<\/h2>\n<p>Ba\u015flang\u0131\u00e7 olarak, yapay zeka taray\u0131c\u0131lar\u0131 hakk\u0131nda biraz bilgi edelim. Yapay zekan\u0131n, internette arama yapma gibi tan\u0131d\u0131k bir s\u00fcreci tamamen de\u011fi\u015ftirmesi ya da en az\u0131ndan <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/ai-browser-security-privacy-risks\/13779\/\" target=\"_blank\" rel=\"noopener\">d\u00f6n\u00fc\u015ft\u00fcrmesi<\/a> fikri, 2023 ile 2024 y\u0131llar\u0131 aras\u0131nda g\u00fcndeme gelmeye ba\u015flad\u0131. Ayn\u0131 d\u00f6nemde, yapay zekay\u0131 \u00e7evrimi\u00e7i aramalara entegre etmek i\u00e7in ilk giri\u015fimler ger\u00e7ekle\u015ftirildi.<\/p>\n<p>Ba\u015flang\u0131\u00e7ta bunlar, <a href=\"https:\/\/support.microsoft.com\/tr-tr\/topic\/microsoft-edge-de-copilot-kullanmaya-ba%C5%9Flarken-ab0153dc-ad31-4de6-899a-802223821a9d\" target=\"_blank\" rel=\"noopener nofollow\">Microsoft Edge Copilot<\/a> ve <a href=\"https:\/\/brave.com\/leo\/\" target=\"_blank\" rel=\"noopener nofollow\">Brave Leo<\/a> gibi geleneksel taray\u0131c\u0131larda yapay zeka kenar \u00e7ubuklar\u0131 olarak uygulanan ek \u00f6zelliklerdi. Sayfalar\u0131 \u00f6zetlemek, sorular\u0131 yan\u0131tlamak ve sitelerde gezinmek i\u00e7in taray\u0131c\u0131 arabirimine yerle\u015fik yard\u0131mc\u0131lar eklediler. 2025 y\u0131l\u0131na kadar, bu konseptin geli\u015fimi, Perplexity AI\u2019dan Comet\u2019i ortaya \u00e7\u0131kard\u0131. <a href=\"https:\/\/www.perplexity.ai\/hub\/blog\/introducing-comet\" target=\"_blank\" rel=\"noopener nofollow\">Comet<\/a>, ba\u015ftan sona kullan\u0131c\u0131-yapay zeka etkile\u015fimi i\u00e7in tasarlanm\u0131\u015f ilk taray\u0131c\u0131d\u0131r.<\/p>\n<p>Bu, yapay zekay\u0131 Comet\u2019in arabiriminin sadece bir eklentisi de\u011fil, merkezinde yer alan bir unsur haline getirdi; arama, analiz ve i\u015f otomasyonunu sorunsuz bir deneyim halinde birle\u015ftirdi. K\u0131sa bir s\u00fcre sonra, Ekim 2025\u2019te OpenAI, ayn\u0131 konsept etraf\u0131nda geli\u015ftirilen kendi yapay zeka taray\u0131c\u0131s\u0131 <a href=\"https:\/\/openai.com\/tr-TR\/index\/introducing-chatgpt-atlas\/\" target=\"_blank\" rel=\"noopener nofollow\">Atlas<\/a>\u2018\u0131 tan\u0131tt\u0131.<\/p>\n<p>Comet\u2019in ana arabirim \u00f6gesi, ekran\u0131n ortas\u0131nda bulunan ve kullan\u0131c\u0131n\u0131n yapay zeka ile etkile\u015fim kurdu\u011fu giri\u015f \u00e7ubu\u011fudur. Atlas i\u00e7in de durum ayn\u0131d\u0131r.<\/p>\n<div id=\"attachment_14024\" style=\"width: 2061px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2025\/12\/01232402\/ai-sidebar-spoofing-atlas-comet-1-EN.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-14024\" class=\"size-full wp-image-14024\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2025\/12\/01232402\/ai-sidebar-spoofing-atlas-comet-1-EN.png\" alt=\"Yeni nesil yapay zeka taray\u0131c\u0131lar: Comet ve Atlas\" width=\"2051\" height=\"2136\"><\/a><p id=\"caption-attachment-14024\" class=\"wp-caption-text\">Comet ve Atlas\u2019\u0131n ana ekranlar\u0131 benzer bir konsepti yans\u0131t\u0131yor: Merkezi bir giri\u015f \u00e7ubu\u011fu ve web ile etkile\u015fim kurman\u0131n birincil y\u00f6ntemi haline gelen yerle\u015fik yapay zeka ile minimalist bir arabirim.<\/p><\/div>\n<p>Ayr\u0131ca, yapay zeka taray\u0131c\u0131lar\u0131 kullan\u0131c\u0131lar\u0131n web sayfas\u0131nda do\u011frudan yapay zeka ile etkile\u015fime girmesine olanak tan\u0131r. Bunu, i\u00e7eri\u011fi analiz eden ve sorgular\u0131 i\u015fleyen yerle\u015fik bir kenar \u00e7ubu\u011fu arac\u0131l\u0131\u011f\u0131yla, kullan\u0131c\u0131n\u0131n sayfadan ayr\u0131lmas\u0131na gerek kalmadan yaparlar. Kullan\u0131c\u0131, mevcut sayfada kalarak yapay zekadan bir makaleyi \u00f6zetlemesini, bir terimi a\u00e7\u0131klamas\u0131n\u0131, verileri kar\u015f\u0131la\u015ft\u0131rmas\u0131n\u0131 veya bir komut olu\u015fturmas\u0131n\u0131 isteyebilir.<\/p>\n<div id=\"attachment_14026\" style=\"width: 2537px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2025\/12\/01232647\/ai-sidebar-spoofing-atlas-comet-2-EN.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-14026\" class=\"size-full wp-image-14026\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2025\/12\/01232647\/ai-sidebar-spoofing-atlas-comet-2-EN.png\" alt=\"Web sayfalar\u0131nda do\u011frudan yapay zeka ile etkile\u015fim kurma\" width=\"2527\" height=\"2792\"><\/a><p id=\"caption-attachment-14026\" class=\"wp-caption-text\">Comet ve Atlas\u2019taki kenar \u00e7ubuklar\u0131, kullan\u0131c\u0131lar\u0131n ayr\u0131 sekmelere gitmeden yapay zekaya sorgu yapmalar\u0131n\u0131 sa\u011flar. Taray\u0131c\u0131da a\u00e7\u0131k durumda olan siteyi analiz edebilir, sorular sorabilir ve bulundu\u011funuz sayfan\u0131n ba\u011flam\u0131 i\u00e7inde yan\u0131tlar alabilirsiniz.<\/p><\/div>\n<p>Bu entegrasyon d\u00fczeyi, kullan\u0131c\u0131lar\u0131n yerle\u015fik yapay zeka taraf\u0131ndan sa\u011flanan cevaplar\u0131 ve talimatlar\u0131 do\u011fal kabul etmelerini sa\u011flar. Bir asistan, arabirimine sorunsuz bir \u015fekilde entegre edildi\u011finde ve sistemin do\u011fal bir par\u00e7as\u0131 gibi hissedildi\u011finde, \u00e7o\u011fu ki\u015fi onun \u00f6nerdi\u011fi eylemleri iki kez kontrol etmek i\u00e7in nadiren durur.<\/p>\n<p>Bu g\u00fcven, ara\u015ft\u0131rmac\u0131lar taraf\u0131ndan yap\u0131lan sald\u0131r\u0131n\u0131n tam olarak istismar etti\u011fi \u015feydir. Sahte bir yapay zeka kenar \u00e7ubu\u011fu, kullan\u0131c\u0131y\u0131 k\u00f6t\u00fc ama\u00e7l\u0131 komutlar\u0131 y\u00fcr\u00fctmeye veya kimlik av\u0131 web sitelerini ziyaret etmeye y\u00f6nlendiren yanl\u0131\u015f talimatlar verebilir.<\/p>\n<h2>Ara\u015ft\u0131rmac\u0131lar yapay zeka kenar \u00e7ubu\u011fu aldatma sald\u0131r\u0131s\u0131n\u0131 nas\u0131l ger\u00e7ekle\u015ftirdiler?<\/h2>\n<p>Sald\u0131r\u0131, kullan\u0131c\u0131n\u0131n k\u00f6t\u00fc ama\u00e7l\u0131 bir uzant\u0131 y\u00fcklemesiyle ba\u015flar. K\u00f6t\u00fc ama\u00e7l\u0131 eylemlerini ger\u00e7ekle\u015ftirmek i\u00e7in, ziyaret edilen t\u00fcm sitelerdeki verileri g\u00f6r\u00fcnt\u00fcleme ve de\u011fi\u015ftirme izinlerinin yan\u0131 s\u0131ra istemci taraf\u0131ndaki veri depolama API\u2019\u0131na eri\u015fim izni gerekir.<\/p>\n<p>Bunlar\u0131n hepsi olduk\u00e7a standart izinlerdir; ilki olmadan hi\u00e7bir taray\u0131c\u0131 uzant\u0131s\u0131 \u00e7al\u0131\u015fmaz. Bu nedenle, yeni bir uzant\u0131 bu izinleri talep etti\u011finde kullan\u0131c\u0131n\u0131n \u015f\u00fcphelenme olas\u0131l\u0131\u011f\u0131 neredeyse s\u0131f\u0131rd\u0131r. Taray\u0131c\u0131 uzant\u0131lar\u0131 ve bunlar\u0131n talep etti\u011fi izinler hakk\u0131nda daha fazla bilgiyi, <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/dangers-of-browser-extensions\/11016\/\" target=\"_blank\" rel=\"noopener\"><strong>Taray\u0131c\u0131 uzant\u0131lar\u0131: sand\u0131\u011f\u0131n\u0131zdan daha tehlikeli<\/strong><\/a> ba\u015fl\u0131kl\u0131 yaz\u0131m\u0131zda bulabilirsiniz.<\/p>\n<div id=\"attachment_14027\" style=\"width: 1410px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2025\/12\/01232755\/ai-sidebar-spoofing-atlas-comet-3.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-14027\" class=\"size-full wp-image-14027\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2025\/12\/01232755\/ai-sidebar-spoofing-atlas-comet-3.jpg\" alt=\"Comet'in uzant\u0131 y\u00f6netimi sayfas\u0131\" width=\"1400\" height=\"887\"><\/a><p id=\"caption-attachment-14027\" class=\"wp-caption-text\">Comet kullan\u0131c\u0131 arabiriminde y\u00fckl\u00fc uzant\u0131lar\u0131n listesi. Gizlenmi\u015f k\u00f6t\u00fc ama\u00e7l\u0131 uzant\u0131 olan AI Marketing Tool, bunlar\u0131n aras\u0131nda g\u00f6ze \u00e7arp\u0131yor. <a href=\"https:\/\/labs.sqrx.com\/ai-sidebar-spoofing-720e0c91d290\" target=\"_blank\" rel=\"nofollow noopener\">Kaynak<\/a><\/p><\/div>\n<p>Y\u00fcklendikten sonra, uzant\u0131 web sayfas\u0131na JavaScript ekler ve ger\u00e7e\u011fine \u00e7ok benzeyen sahte bir kenar \u00e7ubu\u011fu olu\u015fturur. Bu, kullan\u0131c\u0131da herhangi bir \u015f\u00fcphe uyand\u0131rmamal\u0131d\u0131r: Uzant\u0131 bir sorgu ald\u0131\u011f\u0131nda, yasal LLM ile ileti\u015fim kurar ve yan\u0131t\u0131n\u0131 sad\u0131k bir \u015fekilde g\u00f6r\u00fcnt\u00fcler. Ara\u015ft\u0131rmac\u0131lar deneylerinde Google Gemini\u2019\u0131 kulland\u0131lar, ancak OpenAI\u2019\u0131n ChatGPT\u2019si de ayn\u0131 \u015fekilde i\u015fe yarayabilirdi.<\/p>\n<div id=\"attachment_14028\" style=\"width: 1410px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2025\/12\/01232904\/ai-sidebar-spoofing-atlas-comet-4.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-14028\" class=\"size-full wp-image-14028\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2025\/12\/01232904\/ai-sidebar-spoofing-atlas-comet-4.jpg\" alt=\"Yapay zeka kenar \u00e7ubu\u011fu kullan\u0131c\u0131 aray\u00fcz\u00fc aldatmacas\u0131\" width=\"1400\" height=\"793\"><\/a><p id=\"caption-attachment-14028\" class=\"wp-caption-text\">Ekran g\u00f6r\u00fcnt\u00fcs\u00fc, orijinal Comet Assistant\u2019a g\u00f6rsel olarak \u00e7ok benzeyen sahte bir kenar \u00e7ubu\u011funun \u00f6rne\u011fini g\u00f6stermektedir. <a href=\"https:\/\/labs.sqrx.com\/ai-sidebar-spoofing-720e0c91d290\" target=\"_blank\" rel=\"nofollow noopener\">Kaynak<\/a><\/p><\/div>\n<p>Sahte kenar \u00e7ubu\u011fu, potansiyel sald\u0131rgan taraf\u0131ndan \u00f6nceden belirlenen belirli konulara veya anahtar sorgulara verilen yan\u0131tlar\u0131 se\u00e7ici olarak manip\u00fcle edebilir. Bu, \u00e7o\u011fu durumda uzant\u0131n\u0131n yaln\u0131zca yasal yapay zeka yan\u0131tlar\u0131n\u0131 g\u00f6sterece\u011fi, ancak <em>belirli durumlarda<\/em> bunun yerine k\u00f6t\u00fc ama\u00e7l\u0131 talimatlar, ba\u011flant\u0131lar veya komutlar g\u00f6sterece\u011fi anlam\u0131na gelir.<\/p>\n<p>\u015e\u00fcphelenmeyen bir kullan\u0131c\u0131n\u0131n, yukar\u0131da a\u00e7\u0131klanan eylemleri ger\u00e7ekle\u015ftirebilen k\u00f6t\u00fc ama\u00e7l\u0131 bir uzant\u0131y\u0131 y\u00fcklemesi senaryosu ne kadar ger\u00e7ek\u00e7i? Deneyimler, bunun y\u00fcksek olas\u0131l\u0131k oldu\u011funu g\u00f6stermektedir. Blogumuzda, resmi Chrome Web Ma\u011fazas\u0131\u2019na ba\u015far\u0131yla giren d\u00fczinelerce k\u00f6t\u00fc ama\u00e7l\u0131 ve \u015f\u00fcpheli uzant\u0131 hakk\u0131nda defalarca haber yapt\u0131k. Ma\u011faza taraf\u0131ndan yap\u0131lan t\u00fcm g\u00fcvenlik kontrollerine ve Google\u2019\u0131n sahip oldu\u011fu muazzam kaynaklara ra\u011fmen bu durum devam etmektedir. K\u00f6t\u00fc ama\u00e7l\u0131 uzant\u0131lar\u0131n resmi ma\u011fazalara nas\u0131l girdi\u011fine dair daha fazla bilgiyi <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/suspicious-chrome-extensions-with-6-million-installs\/13468\/\" target=\"_blank\" rel=\"noopener\"><strong>57 \u015f\u00fcpheli Chrome uzant\u0131s\u0131 alt\u0131 milyon y\u00fcklemeye ula\u015ft\u0131<\/strong><\/a> ba\u015fl\u0131kl\u0131 yaz\u0131m\u0131zda bulabilirsiniz.<\/p>\n<h2>Yapay zeka kenar \u00e7ubu\u011fu aldatmacas\u0131n\u0131n sonu\u00e7lar\u0131<\/h2>\n<p>\u015eimdi sald\u0131rganlar\u0131n sahte kenar \u00e7ubu\u011funu ne i\u00e7in kullanabileceklerini tart\u0131\u015fal\u0131m. Ara\u015ft\u0131rmac\u0131lar\u0131n belirtti\u011fi gibi, yapay zeka kenar \u00e7ubu\u011fu aldatma sald\u0131r\u0131s\u0131, potansiyel k\u00f6t\u00fc niyetli akt\u00f6rlere zarar verme konusunda geni\u015f f\u0131rsatlar sunmaktad\u0131r. Bunu g\u00f6stermek i\u00e7in ara\u015ft\u0131rmac\u0131lar \u00fc\u00e7 olas\u0131 sald\u0131r\u0131 senaryosu ve bunlar\u0131n sonu\u00e7lar\u0131n\u0131 a\u00e7\u0131klad\u0131: Kripto c\u00fczdan kimlik av\u0131, Google hesab\u0131 h\u0131rs\u0131zl\u0131\u011f\u0131 ve cihaz ele ge\u00e7irme. Her birini daha ayr\u0131nt\u0131l\u0131 bir \u015fekilde inceleyelim.<\/p>\n<h3>Yapay zeka kenar \u00e7ubu\u011fu kullanarak Binance kimlik bilgilerini \u00e7almak<\/h3>\n<p>\u0130lk senaryoda, kullan\u0131c\u0131 kenar \u00e7ubu\u011fundaki yapay zekaya Binance kripto borsas\u0131nda kripto para birimini nas\u0131l satabilece\u011fini sorar. Yapay zeka asistan\u0131, kripto borsas\u0131na bir ba\u011flant\u0131 i\u00e7eren ayr\u0131nt\u0131lar\u0131n oldu\u011fu bir cevap verir. Ancak bu ba\u011flant\u0131 ger\u00e7ek Binance sitesine de\u011fil, olduk\u00e7a ikna edici sahte bir siteye; <strong>binacee<\/strong> sahte alan ad\u0131n\u0131 kullanan sald\u0131rgan\u0131n kimlik av\u0131 sitesine y\u00f6nlendirir.<\/p>\n<div id=\"attachment_14029\" style=\"width: 1410px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2025\/12\/01233017\/ai-sidebar-spoofing-atlas-comet-5.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-14029\" class=\"size-full wp-image-14029\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2025\/12\/01233017\/ai-sidebar-spoofing-atlas-comet-5.jpg\" alt=\"Binance gibi g\u00f6r\u00fcnen kimlik av\u0131 sayfas\u0131\" width=\"1400\" height=\"789\"><\/a><p id=\"caption-attachment-14029\" class=\"wp-caption-text\">login{.}binacee{.}com alan ad\u0131ndaki sahte oturum a\u00e7ma formu, orijinalinden neredeyse ay\u0131rt edilemez ve kullan\u0131c\u0131 kimlik bilgilerini \u00e7almak i\u00e7in tasarlanm\u0131\u015ft\u0131r. <a href=\"https:\/\/labs.sqrx.com\/ai-sidebar-spoofing-720e0c91d290\" target=\"_blank\" rel=\"nofollow noopener\">Kaynak<\/a><\/p><\/div>\n<p>Ard\u0131ndan, hi\u00e7bir \u015feyden \u015f\u00fcphelenmeyen kullan\u0131c\u0131 Binance kimlik bilgilerini ve gerekirse iki fakt\u00f6rl\u00fc kimlik do\u011frulama kodunu girer. Bundan sonra, sald\u0131rganlar kurban\u0131n hesab\u0131na tam eri\u015fim elde eder ve kripto c\u00fczdanlar\u0131ndan t\u00fcm paray\u0131 \u00e7ekebilirler.<\/p>\n<h3>Sahte bir yapay zeka kenar \u00e7ubu\u011fu kullanarak bir Google hesab\u0131n\u0131 ele ge\u00e7irmek<\/h3>\n<p>Bir sonraki sald\u0131r\u0131 varyasyonu da bir kimlik av\u0131 ba\u011flant\u0131s\u0131yla ba\u015flar. Bu durumda sahte bir dosya payla\u015f\u0131m hizmetine y\u00f6nlendirir. Kullan\u0131c\u0131 ba\u011flant\u0131ya t\u0131klarsa, a\u00e7\u0131l\u0131\u015f sayfas\u0131 Google hesab\u0131yla hemen oturum a\u00e7mas\u0131n\u0131 isteyen bir web sitesine y\u00f6nlendirilir.<\/p>\n<p>Kullan\u0131c\u0131 bu se\u00e7ene\u011fi t\u0131klad\u0131ktan sonra, kimlik bilgilerini girmesi i\u00e7in <em>resmi <\/em>Google giri\u015f sayfas\u0131na y\u00f6nlendirilir, ancak daha sonra sahte platform, kullan\u0131c\u0131n\u0131n Google Drive ve Gmail\u2019ine tam eri\u015fim izni ister.<\/p>\n<div id=\"attachment_14030\" style=\"width: 1410px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2025\/12\/01233131\/ai-sidebar-spoofing-atlas-comet-6.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-14030\" class=\"size-full wp-image-14030\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2025\/12\/01233131\/ai-sidebar-spoofing-atlas-comet-6.jpg\" alt=\"Google hesab\u0131na eri\u015fim talebi\" width=\"1400\" height=\"749\"><\/a><p id=\"caption-attachment-14030\" class=\"wp-caption-text\">Sahte uygulama share-sync-pro{.}vercel{.}app, kullan\u0131c\u0131n\u0131n Gmail ve Google Drive\u2019\u0131na tam eri\u015fim izni talep eder. Bu, sald\u0131rganlara hesap \u00fczerinde kontrol sa\u011flar. <a href=\"https:\/\/labs.sqrx.com\/ai-sidebar-spoofing-720e0c91d290\" target=\"_blank\" rel=\"nofollow noopener\">Kaynak<\/a><\/p><\/div>\n<p>Kullan\u0131c\u0131 sayfay\u0131 dikkatlice incelemeden otomatik olarak <em>\u0130zin Ver<\/em>\u2018e t\u0131klarsa, sald\u0131rganlara son derece tehlikeli eylemler ger\u00e7ekle\u015ftirmeleri i\u00e7in izin vermi\u015f olur:<\/p>\n<ul>\n<li>E-postalar\u0131n\u0131 ve ayarlar\u0131n\u0131 g\u00f6r\u00fcnt\u00fcleme.<\/li>\n<li>Gmail hesaplar\u0131ndan e-postalar\u0131 okuma, olu\u015fturma ve g\u00f6nderme.<\/li>\n<li>Google Drive\u2019da depolad\u0131klar\u0131 t\u00fcm dosyalar\u0131 g\u00f6r\u00fcnt\u00fcleme ve indirme.<\/li>\n<\/ul>\n<p>Bu <a href=\"https:\/\/developers.google.com\/identity\/protocols\/oauth2\/web-server?hl=tr-tr\" target=\"_blank\" rel=\"noopener nofollow\">eri\u015fim d\u00fczeyi<\/a>, siber su\u00e7lulara kurban\u0131n dosyalar\u0131n\u0131 \u00e7alma, o e-posta adresine ba\u011fl\u0131 hizmetleri ve hesaplar\u0131 kullanma ve hesap sahibinin kimli\u011fine b\u00fcr\u00fcnerek kimlik av\u0131 mesajlar\u0131 yayma olana\u011f\u0131 verir.<\/p>\n<h3>Sahte yapay zeka taraf\u0131ndan olu\u015fturulan yard\u0131mc\u0131 program kurulum k\u0131lavuzu arac\u0131l\u0131\u011f\u0131yla ba\u015flat\u0131lan ters kabuk<\/h3>\n<p>Son olarak, son senaryoda kullan\u0131c\u0131 yapay zekaya belirli bir uygulaman\u0131n nas\u0131l kurulaca\u011f\u0131n\u0131 sorar. \u00d6rnekte Homebrew yard\u0131mc\u0131 program\u0131 kullan\u0131lm\u0131\u015ft\u0131r, ancak bu herhangi bir \u015fey olabilir. Kenar \u00e7ubu\u011fu, kullan\u0131c\u0131ya tamamen mant\u0131kl\u0131, yapay zeka taraf\u0131ndan olu\u015fturulan bir k\u0131lavuz g\u00f6sterir. Son a\u015famaya kadar t\u00fcm ad\u0131mlar makul ve do\u011fru g\u00f6r\u00fcn\u00fcr, ancak son a\u015famada yard\u0131mc\u0131 program kurulum komutu <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/remote-shell\/\" target=\"_blank\" rel=\"noopener\">ters kabuk<\/a> ile de\u011fi\u015ftirilir.<\/p>\n<div id=\"attachment_14031\" style=\"width: 1410px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2025\/12\/01233417\/ai-sidebar-spoofing-atlas-comet-7.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-14031\" class=\"size-full wp-image-14031\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2025\/12\/01233417\/ai-sidebar-spoofing-atlas-comet-7.jpg\" alt=\"Sahte k\u0131lavuz, kurulum komutu yerine ters kabuk i\u00e7erir.\" width=\"1400\" height=\"866\"><\/a><p id=\"caption-attachment-14031\" class=\"wp-caption-text\">Kenar \u00e7ubu\u011funda g\u00f6sterilen yard\u0131mc\u0131 program\u0131 y\u00fckleme k\u0131lavuzu neredeyse tamamen do\u011frudur, ancak son ad\u0131mda ters kabuk komutu bulunmaktad\u0131r. <a href=\"https:\/\/labs.sqrx.com\/ai-sidebar-spoofing-720e0c91d290\" target=\"_blank\" rel=\"nofollow noopener\">Kaynak<\/a><\/p><\/div>\n<p>Kullan\u0131c\u0131, k\u00f6t\u00fc ama\u00e7l\u0131 kodu kopyalay\u0131p terminale yap\u0131\u015ft\u0131rarak ve ard\u0131ndan \u00e7al\u0131\u015ft\u0131rarak yapay zekan\u0131n talimatlar\u0131n\u0131 izlerse, sistemi tehlikeye girer. Sald\u0131rganlar, cihazdan veri indirebilir, etkinlikleri izleyebilir veya k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m y\u00fckleyerek sald\u0131r\u0131ya devam edebilirler. Bu senaryo, g\u00fcvenilir bir yapay zeka arabiriminde tek bir sat\u0131r kodun de\u011fi\u015ftirilmesinin bir cihaz\u0131 tamamen tehlikeye atabilece\u011fini a\u00e7\u0131k\u00e7a g\u00f6stermektedir.<\/p>\n<h2>Sahte yapay zeka kenar \u00e7ubuklar\u0131n\u0131n kurban\u0131 olmamak i\u00e7in ne yapmal\u0131?<\/h2>\n<p>Yapay zeka kenar \u00e7ubu\u011fu sahtekarl\u0131k sald\u0131r\u0131s\u0131 \u015femas\u0131 \u015fu anda sadece teorik olarak mevcuttur. Ancak, son y\u0131llarda sald\u0131rganlar varsay\u0131msal tehditleri pratik sald\u0131r\u0131lara d\u00f6n\u00fc\u015ft\u00fcrmede \u00e7ok h\u0131zl\u0131 davranmaktad\u0131rlar. Bu nedenle, baz\u0131 k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m geli\u015ftiricilerinin sahte bir yapay zeka kenar \u00e7ubu\u011fu kullanan k\u00f6t\u00fc ama\u00e7l\u0131 bir uzant\u0131 \u00fczerinde yo\u011fun bir \u015fekilde \u00e7al\u0131\u015ft\u0131klar\u0131 veya bunu resmi bir uzant\u0131 ma\u011fazas\u0131na y\u00fckledikleri olduk\u00e7a olas\u0131d\u0131r.<\/p>\n<p>Bu nedenle, tan\u0131d\u0131k bir taray\u0131c\u0131 arabiriminin bile <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/phishing-with-progressive-web-apps\/12482\/\" target=\"_blank\" rel=\"noopener\">g\u00fcvenli\u011finin ihlal edilebilece\u011fini<\/a> unutmamak \u00f6nemlidir. Talimatlar ikna edici g\u00f6r\u00fcnse ve taray\u0131c\u0131 i\u00e7i yapay zeka asistan\u0131ndan gelse bile, onlara k\u00f6r\u00fc k\u00f6r\u00fcne g\u00fcvenmemelisiniz. Sahte yapay zeka i\u00e7eren bir sald\u0131r\u0131n\u0131n kurban\u0131 olmamak i\u00e7in size yard\u0131mc\u0131 olacak son birka\u00e7 ipucu:<\/p>\n<ul>\n<li>Yapay zeka asistanlar\u0131n\u0131 kullan\u0131rken, yapay zekan\u0131n \u00f6nerilerini uygulamadan \u00f6nce t\u00fcm komutlar\u0131 ve ba\u011flant\u0131lar\u0131 dikkatlice kontrol edin.<\/li>\n<li>Yapay zeka herhangi bir programlama kodunun \u00e7al\u0131\u015ft\u0131r\u0131lmas\u0131n\u0131 \u00f6nerirse, bu kodu kopyalay\u0131n ve yapay zeka olmayan <em>farkl\u0131<\/em> bir taray\u0131c\u0131da arama motoruna yap\u0131\u015ft\u0131rarak ne i\u015fe yarad\u0131\u011f\u0131n\u0131 \u00f6\u011frenin.<\/li>\n<li>Kesinlikle gerekli olmad\u0131k\u00e7a, yapay zeka veya ba\u015fka t\u00fcrden taray\u0131c\u0131 uzant\u0131lar\u0131 y\u00fcklemeyin. Art\u0131k kullanmad\u0131\u011f\u0131n\u0131z uzant\u0131lar\u0131 d\u00fczenli olarak temizleyin ve silin.<\/li>\n<li>Bir uzant\u0131y\u0131 y\u00fcklemeden \u00f6nce kullan\u0131c\u0131 yorumlar\u0131n\u0131 okuyun. \u00c7o\u011fu k\u00f6t\u00fc ama\u00e7l\u0131 uzant\u0131, ma\u011faza moderat\u00f6rleri bunlar\u0131 kald\u0131rmaya vakit bulamadan \u00e7ok \u00f6nce, aldat\u0131lan kullan\u0131c\u0131lar taraf\u0131ndan \u00e7ok say\u0131da sert ele\u015ftiri al\u0131r.<\/li>\n<li>Kimlik bilgilerinizi veya di\u011fer gizli bilgilerinizi girmeden \u00f6nce, web sitesinin adresinin \u015f\u00fcpheli g\u00f6r\u00fcnmedi\u011fini ve yaz\u0131m hatas\u0131 i\u00e7ermedi\u011fini her zaman kontrol edin. \u00dcst d\u00fczey etki alan\u0131na da dikkat edin; resmi etki alan\u0131 olmal\u0131d\u0131r.<\/li>\n<li>Parolalar\u0131 saklamak i\u00e7in <a href=\"https:\/\/www.kaspersky.com.tr\/password-manager?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener\">Kaspersky Password Manager<\/a>\u00a0kullan\u0131n. Siteyi tan\u0131maz ve otomatik olarak kullan\u0131c\u0131 ad\u0131 ve parola alanlar\u0131n\u0131 doldurmay\u0131 \u00f6nermezse, bu, bir kimlik av\u0131 sayfas\u0131nda olup olmad\u0131\u011f\u0131n\u0131z\u0131 kendinize sorman\u0131z i\u00e7in g\u00fc\u00e7l\u00fc bir nedendir.<\/li>\n<li>Cihaz\u0131n\u0131zdaki \u015f\u00fcpheli etkinlikleri size bildiren ve kimlik av\u0131 sitelerini ziyaret etmenizi engelleyen <a href=\"https:\/\/www.kaspersky.com.tr\/premium?icid=tr_bb2023-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener\">g\u00fcvenilir bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc<\/a> y\u00fckleyin.<\/li>\n<\/ul>\n<blockquote><p>Taray\u0131c\u0131larda sizi bekleyen yapay zeka destekli veya normal di\u011fer tehditler nelerdir:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.kaspersky.com.tr\/blog\/ai-browser-security-privacy-risks\/13779\/\" target=\"_blank\" rel=\"noopener\">Yapay zeka destekli taray\u0131c\u0131lar\u0131n art\u0131lar\u0131 ve eksileri<\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com.tr\/blog\/types-of-cookie-files-and-how-to-protect-them\/13751\/\" target=\"_blank\" rel=\"noopener\">\u00c7erezleri kapmak: Hackerlar neden \u00e7erezleri bu kadar \u00e7ok seviyor?<\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com.tr\/blog\/visited-links-privacy-protection\/13349\/\" target=\"_blank\" rel=\"noopener\">Mora d\u00f6n\u00fc\u015fen ba\u011flant\u0131lar: Ziyaret edilen ba\u011flant\u0131lar gizlili\u011finizi nas\u0131l tehdit ediyor?<\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com.tr\/blog\/best-private-browser-in-2025\/13233\/\" target=\"_blank\" rel=\"noopener\">Gizlilik sald\u0131r\u0131 alt\u0131nda: Chrome, Edge ve Firefox\u2019ta k\u00f6t\u00fc s\u00fcrprizler<\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com.tr\/blog\/dangerous-browser-extensions-2023\/11947\/\" target=\"_blank\" rel=\"noopener\">Tehlikeli taray\u0131c\u0131 uzant\u0131lar\u0131<\/a><\/li>\n<\/ul>\n<\/blockquote>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-geek\">\n","protected":false},"excerpt":{"rendered":"<p>K\u00f6t\u00fc ama\u00e7l\u0131 uzant\u0131lar, Comet ve Atlas taray\u0131c\u0131lar\u0131nda yapay zeka kenar \u00e7ubuklar\u0131n\u0131 nas\u0131l taklit edebilir, kullan\u0131c\u0131 sorgular\u0131n\u0131 nas\u0131l engelleyebilir ve model yan\u0131tlar\u0131n\u0131 nas\u0131l manip\u00fcle edebilir?<\/p>\n","protected":false},"author":2726,"featured_media":14022,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[1425,1074,2802,1749,537,1750,1424],"class_list":{"0":"post-14021","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-ai","9":"tag-kimlik-avi","10":"tag-llm","11":"tag-tarayicilar","12":"tag-tehditler","13":"tag-uzantilar","14":"tag-yapay-zeka"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/ai-sidebar-spoofing-atlas-comet\/14021\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/ai-sidebar-spoofing-atlas-comet\/29827\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/ai-sidebar-spoofing-atlas-comet\/24898\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/ai-sidebar-spoofing-atlas-comet\/13004\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/ai-sidebar-spoofing-atlas-comet\/29729\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/ai-sidebar-spoofing-atlas-comet\/28763\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/ai-sidebar-spoofing-atlas-comet\/31650\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/ai-sidebar-spoofing-atlas-comet\/30298\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/ai-sidebar-spoofing-atlas-comet\/40876\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/ai-sidebar-spoofing-atlas-comet\/54769\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/ai-sidebar-spoofing-atlas-comet\/23391\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/ai-sidebar-spoofing-atlas-comet\/32918\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/ai-sidebar-spoofing-atlas-comet\/29949\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/ai-sidebar-spoofing-atlas-comet\/35663\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/ai-sidebar-spoofing-atlas-comet\/35290\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/yapay-zeka\/","name":"yapay zeka"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/14021","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2726"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=14021"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/14021\/revisions"}],"predecessor-version":[{"id":14025,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/14021\/revisions\/14025"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/14022"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=14021"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=14021"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=14021"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}