{"items":[{"id":"e751f0053bbcf0530ee14e4290d53c95f6b0d86a","incidentId":"271d7e3fa6360510e7156cfd6dc8b64b8b999096","title":"AI Agents Are Hacking Online Retailers for $25 a Company","summary":"A financially motivated threat actor, apparently operating from China, is using open-source AI agent frameworks (Strix for scanning, Cairn for autonomous exploitation, and Hermes powered by claude-opus-4.6 for orchestration) to autonomously attack hundreds of online retailers at scale, per cybersecurity startup Gambit. The campaign, active since July 2026, has compromised at least 119 websites with credit card skimmers and stolen more than 600,000 valid card records, breaching a Fortune 500 hospitality company, a major U.S. airline, and other large organizations.","whyItMatters":"The campaign demonstrates fully autonomous AI agents executing the entire intrusion-to-exfiltration chain against tens of companies per day at roughly $25 per target, marking a real-world shift toward scalable, agent-driven cybercrime that defenders must anticipate.","threatTypeTags":["agentic-attack-framework","autonomous-exploitation","malicious-ai-agents","data-exfiltration","supply-chain","web-skimmer"],"affectedTechTags":["ai-agents","llm"],"threatActor":"SOUL (Red Team Operator persona)","relevanceScore":0.97,"severityScore":0.9,"sources":[{"sourceId":"hn-search","title":"AI Agents Are Hacking Online Retailers for $25 a Company","link":"https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company"},{"sourceId":"bleepingcomputer","title":"Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers","link":"https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/"},{"sourceId":"theregister","title":"Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs","link":"https://www.theregister.com/security/2026/09/25/crook-used-three-open-source-agents-to-break-into-a-fortune-500-hospitality-company-a-major-us-airline-and-25-other-orgs/5299012"}],"sourceItemIds":["8f2479d607e94f5d7096e03f47d361c51c3e6869","1224a413dc06b22071ae3c9be1f9a9247f41d84f","ce306b981d9f37701041fa3d74cb9c84076348d5"],"publishedAt":"2026-09-24T23:32:15.000Z","firstReportedAt":"2026-09-22T22:00:20.000Z","curatedAt":"2026-09-23T02:00:37.791Z","itemType":"incident","threatStatus":"in-the-wild","contentClass":"threat","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/","domain":"bleepingcomputer.com","slug":"bleepingcomputer","tier":"known","title":"Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers","pageTitle":"Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers"},{"role":"aggregator","url":"https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company","domain":"gambit.security","slug":null,"tier":"unknown","title":"AI Agents Are Hacking Online Retailers for $25 a Company","pageTitle":"AI Agents Are Hacking Online Retailers for $25 a Company"},{"role":"aggregator","url":"https://www.theregister.com/security/2026/09/25/crook-used-three-open-source-agents-to-break-into-a-fortune-500-hospitality-company-a-major-us-airline-and-25-other-orgs/5299012","domain":"theregister.com","slug":"theregister","tier":"known","title":"Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs","pageTitle":"Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs"}]},{"id":"29b2ff815d16b483bb1a35d3c50438f912cc7184","incidentId":"a7e56890faf5de4e74e46c95c39625317348234c","title":"'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing","summary":"Researchers at Zenity disclosed three vulnerabilities in Salesforce Agentforce, collectively dubbed 'Salesbleed,' that let attackers smuggle arbitrary instructions through Web-to-lead forms into agentic workflows. Chained together, the flaws enable slow data exfiltration of internal customer data and allow attackers to phish employees from within trusted internal Slack channels.","whyItMatters":"Salesbleed shows how indirect prompt injection through public-facing forms can traverse multiple connected apps and turn a trusted internal Slack channel into a phishing vector, a serious risk for enterprises deploying interconnected AI agents.","threatTypeTags":["indirect-prompt-injection","data-exfiltration","phishing","tool-abuse"],"affectedTechTags":["ai-agents","llm","salesforce-agentforce","slack"],"threatActor":null,"relevanceScore":0.95,"severityScore":0.72,"sources":[{"sourceId":"theregister","title":"Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing","link":"https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958"},{"sourceId":"darkreading","title":"'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing","link":"https://www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishing"}],"sourceItemIds":["7c4472dca036f8b93c4e75520f97ecebe6e8f9b9","740615b6aa15baa2268d6d722d318eff59e8a234"],"publishedAt":"2026-09-24T21:04:03.000Z","firstReportedAt":"2026-09-24T19:01:15.000Z","curatedAt":"2026-09-24T19:30:31.791Z","itemType":"incident","threatStatus":"disclosed","contentClass":"threat","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishing","domain":"darkreading.com","slug":"darkreading","tier":"known","title":"'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing","pageTitle":"'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing"},{"role":"aggregator","url":"https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958","domain":"theregister.com","slug":"theregister","tier":"known","title":"Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing","pageTitle":"Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing"}]},{"id":"300ea944795a17ea2a7bf7412ead2d2119556d31","incidentId":"c41765553ede55787b6cff24941df45dd1acb664","title":"New Carbonato malware uses AI agents to hijack exposed Docker hosts","summary":"Carbonato is a new worm-like botnet malware that hijacks insecure Docker daemons exposed on port 2375 and installs the Hermes Agent AI framework (using an agent named 'GH0ST') to autonomously execute attacker tasks received via Telegram. Discovered by Malwarebytes/ThreatDown in an exposed Docker registry, the AI agent interprets tasks, writes and runs terminal commands, reads output, and collects AI API keys, SSH credentials, and tokens while spreading to other exposed hosts every five minutes.","whyItMatters":"Carbonato demonstrates real-world weaponization of an autonomous AI agent framework to run an interactive command loop on compromised hosts and self-propagate, showing that agentic AI is now an operational component of in-the-wild botnet malware.","threatTypeTags":["agentic-worm","malicious-ai-agent","autonomous-attack","data-exfiltration","botnet"],"affectedTechTags":["ai-agents","llm","docker","hermes-agent"],"threatActor":null,"relevanceScore":0.95,"severityScore":0.8,"sources":[{"sourceId":"bleepingcomputer","title":"New Carbonato malware uses AI agents to hijack exposed Docker hosts","link":"https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/"}],"sourceItemIds":["bedd358b45926bbba767eb603284862c4a4e9865"],"publishedAt":"2026-09-24T20:10:48.000Z","firstReportedAt":"2026-09-24T20:10:48.000Z","curatedAt":"2026-09-24T21:00:13.400Z","itemType":"incident","threatStatus":"in-the-wild","contentClass":"threat","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/","domain":"bleepingcomputer.com","slug":"bleepingcomputer","tier":"known","title":"New Carbonato malware uses AI agents to hijack exposed Docker hosts","pageTitle":"New Carbonato malware uses AI agents to hijack exposed Docker hosts"}]},{"id":"761a36ee83bd820e18d5c4b6abf1c96df2831207","incidentId":"5cb2c447e4bc695e4dd5e75136db42ee985569d6","title":"⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More","summary":"The Hacker News weekly ThreatsDay/recap bulletin aggregates numerous short security stories, including several agentic-AI items: GhostJacking attacks against agentic kill chains, a Cursor CLI pre-trust execution flaw, indirect prompt injection in web content targeting AI agents, malicious plugins turning AI agents into insider threats, and a threat actor turning frontier AI into an offensive platform, alongside non-AI stories on proxy botnets, crypting services, EtherHiding, and ICS advisories.","whyItMatters":"The roundup surfaces multiple emerging agentic-AI attack techniques—prompt injection against AI agents, coding-assistant CLI flaws, and malicious AI plugins—that defenders monitoring the AI threat landscape should track.","threatTypeTags":["prompt-injection","tool-abuse","agentic-worm","supply-chain","jailbreak"],"affectedTechTags":["ai-agents","llm","copilot","mcp"],"threatActor":null,"relevanceScore":0.5,"severityScore":0.3,"sources":[{"sourceId":"thehackernews","title":"⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More","link":"https://thehackernews.com/2026/07/monday-recap-proxy-botnets-browser.html"},{"sourceId":"thehackernews","title":"ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories","link":"https://thehackernews.com/2026/07/threatsday-android-spyware-plc-attacks.html"},{"sourceId":"firecrawl-search","title":"ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories","link":"https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"},{"sourceId":"firecrawl-search","title":"ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories","link":"https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html?m=1"},{"sourceId":"thehackernews","title":"ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories","link":"https://thehackernews.com/2026/09/threatsday-ai-search-poisoning-ai.html"}],"sourceItemIds":["3b62cb8af4e02da8b0667d59441176e15e1ea730","bf378f58b0cb6215b65bc89ff0f5e5d7179df958","7dfa4281060484f13c06aba845890073690eb247","195ac6da0bb1a38a8e1be5ae4e275ea1a8624110","52d6bb5fe0c9a98a2df787cd07ba1d5ae19289bb","bd19e9a806442ffb7eaaa400f9e3aa8b7296792b"],"publishedAt":"2026-09-24T17:52:43.000Z","firstReportedAt":"2026-07-06T13:01:14.000Z","curatedAt":"2026-07-06T14:00:25.697Z","itemType":"roundup","threatStatus":"unknown","contentClass":"news","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html","domain":"thehackernews.com","slug":"thehackernews","tier":"known","title":"ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories","pageTitle":"ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories"},{"role":"aggregator","url":"https://thehackernews.com/2026/07/monday-recap-proxy-botnets-browser.html","domain":"thehackernews.com","slug":"thehackernews","tier":"known","title":"⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More","pageTitle":"⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More"},{"role":"aggregator","url":"https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html?m=1","domain":"thehackernews.com","slug":"thehackernews","tier":"known","title":"ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories","pageTitle":"ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories"},{"role":"aggregator","url":"https://thehackernews.com/2026/09/threatsday-ai-search-poisoning-ai.html","domain":"thehackernews.com","slug":"thehackernews","tier":"known","title":"ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories","pageTitle":"ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories"},{"role":"aggregator","url":"https://thehackernews.com/2026/07/threatsday-android-spyware-plc-attacks.html","domain":"thehackernews.com","slug":"thehackernews","tier":"known","title":"ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories","pageTitle":"ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories"},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20685","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-20685","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48276","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-48276","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48283","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-48283","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48277","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-48277","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48281","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-48281","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48316","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-48316","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48282","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-48282","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48313","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-48313","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48315","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-48315","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48286","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-48286","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50548","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-50548","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50549","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-50549","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46242","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-46242","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6682","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-6682","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6687","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-6687","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6688","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-6688","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8037","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-8037","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28701","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-28701","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33560","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-33560","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31928","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-31928","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41120","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-41120","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41492","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-41492","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55047","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-55047","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55407","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-55407","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13774","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-13774","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13788","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-13788","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48519","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-48519","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48520","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-48520","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7528","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-7528","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7524","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-7524","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3199","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-3199","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12166","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-12166","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12167","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-12167","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12168","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-12168","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56141","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-56141","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56142","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-56142","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50242","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-50242","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20213","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-20213","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20214","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-20214","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20215","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-20215","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20216","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-20216","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20217","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-20217","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20243","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-20243","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20244","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-20244","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20191","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-20191","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53917","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-53917","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54475","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-54475","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49877","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-49877","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13079","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-13079","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45504","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-45504","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14191","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-14191","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44024","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-44024","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44025","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-44025","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55957","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-55957","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55956","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-55956","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13136","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-13136","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-15660","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2025-15660","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22678","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-22678","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49102","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-49102","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49103","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-49103","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42210","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-42210","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56022","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-56022","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12044","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-12044","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12050","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-12050","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66273","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2025-66273","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66279","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2025-66279","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22893","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-22893","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11310","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-11310","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11999","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-11999","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6679","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-6679","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55958","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-55958","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55960","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-55960","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55961","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-55961","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48611","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-48611","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20896","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-20896","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54068","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2025-54068","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46817","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-46817","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55200","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-55200","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38831","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2023-38831","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21412","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2024-21412","title":null},{"role":"link","url":"https://tenetsecurity.ai/blog/ghostjacking-attacks-agentic-kill-chain/","domain":"tenetsecurity.ai","slug":null,"tier":"unknown","title":"GhostJacking attacks and the agentic kill chain"},{"role":"original","url":"https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents","domain":"zscaler.com","slug":"zscaler","tier":"known","title":"Indirect prompt injection in web content targets AI agents"},{"role":"link","url":"https://www.manifold.security/blog/cursor-cli-worktree-pre-trust-execution","domain":"manifold.security","slug":null,"tier":"unknown","title":"Cursor CLI worktree pre-trust execution"},{"role":"link","url":"https://www.cyberproof.com/blog/how-malicious-plugins-transform-ai-agents-into-insider-threats/","domain":"cyberproof.com","slug":null,"tier":"unknown","title":"How malicious plugins transform AI agents into insider threats"},{"role":"original","url":"https://www.catonetworks.com/blog/cato-ctrl-how-one-threat-actor-turned-frontier-ai-into-an-offensive-platform/","domain":"catonetworks.com","slug":"cato-networks","tier":"known","title":"How one threat actor turned frontier AI into an offensive platform"}]},{"id":"a8aa5bd6e21ac8ef7708648da88f2348806d2975","incidentId":"baaa96ad2dab0e79ce212a00d47e8e8eff6bf20c","title":"Placeholder Domains Whose Ads Serve Scams","summary":"Manifold Security disclosed that unreserved documentation placeholder domains—third-party[.]com, your-domain[.]com and yoursite[.]com—have been registered by attackers and now serve malicious content, including a Windows-gated ClickFix PowerShell lure and macOS scareware/investment-fraud scams via cloaked ad redirects. These domains are hard-coded across 1,700+ GitHub repositories and referenced by more than 1,500 AI agent skills, so every agent, doc, test, or skill pointing at them now directs users to attacker infrastructure. Static text checks miss the threat because the redirect fires only after JavaScript runs in a real browser.","whyItMatters":"Hard-coded placeholder domains embedded in over 1,500 AI agent skills turn a documentation convenience into a live supply-chain vector that can route agents and their users to attacker-controlled malware and scam pages.","threatTypeTags":["supply-chain","clickfix","malvertising","domain-hijack"],"affectedTechTags":["ai-agents","agent-skills","llm"],"threatActor":null,"relevanceScore":0.55,"severityScore":0.55,"sources":[{"sourceId":"thehackernews","title":"Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content","link":"https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html"}],"sourceItemIds":["69911fab466503d5ef74d8eec98dc9ad84674d58"],"publishedAt":"2026-09-24T15:27:32.000Z","firstReportedAt":"2026-09-24T15:27:32.000Z","curatedAt":"2026-09-24T17:00:21.145Z","itemType":"incident","threatStatus":"in-the-wild","contentClass":"threat","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html","domain":"thehackernews.com","slug":"thehackernews","tier":"known","title":"Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content","pageTitle":"Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content"},{"role":"original","url":"https://www.manifold.security/blog/placeholder-domains-ads-serve-scams","domain":"manifold.security","slug":null,"tier":"unknown","sourceTrust":"trusted","title":"Placeholder domains' ads serve scams","pageTitle":"Placeholder Domains Whose Ads Serve Scams","isPrimary":true}]},{"id":"1ebaaf72d2a58d7aeefb80dea05bbf55553e55ce","incidentId":"8306ef112e460df0917447dbb668fcefe1888bc1","title":"Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps","summary":"Varonis Threat Labs disclosed CoSnitch (CVE-2026-24301, CVSS 8.8), a one-click vulnerability chain in Microsoft Copilot Personal that lets a specially crafted Copilot URL auto-execute attacker-supplied instructions on page load. The injected prompt can query connected services (Gmail, Drive, Calendar, OneDrive), encode results into an outbound URL exfiltrated through Copilot's legitimate URL-fetching, and persistently poison Copilot memory via hidden instructions in a webpage submitted for summarization. Microsoft deployed a service-side fix on August 18, 2026; enterprise Copilot was unaffected and no in-the-wild exploitation was observed.","whyItMatters":"CoSnitch shows an AI assistant with broad OAuth access to email, files and calendars can be turned into a silent collection-and-exfiltration channel by a single malicious link, moving sensitive data through a trusted AI workflow that evades traditional alerts.","threatTypeTags":["prompt-injection","indirect-prompt-injection","data-exfiltration","memory-injection","tool-abuse"],"affectedTechTags":["copilot","llm","ai-agents"],"threatActor":null,"relevanceScore":0.97,"severityScore":0.75,"sources":[{"sourceId":"theregister","title":"Copilot tricked into telling reseachers how to hack itself","link":"https://www.theregister.com/research/2026/08/18/copilot-tricked-into-telling-reseachers-how-to-hack-itself/5288857"},{"sourceId":"thehackernews","title":"Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps","link":"https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html"},{"sourceId":"darkreading","title":"'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture","link":"https://www.darkreading.com/vulnerabilities-threats/cosnitch-attack-copilot-mapping-out-architecture"},{"sourceId":"firecrawl-search","title":"CoSnitch Exploit Leaks Copilot Data via Hidden URL Parameter | News","link":"https://getaibook.com/news/cosnitch-exploit-leaks-copilot-data-via-hidden-url-parameter/"},{"sourceId":"firecrawl-search","title":"Microsoft Copilot reveals secret input that allowed it to be hacked - Ars Technica","link":"https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/"},{"sourceId":"firecrawl-search","title":"One Click Attack On Microsoft Copilot","link":"https://www.cybersecurityintelligence.com/blog/one-click-attack-on-microsoft-copilot-9651.html"},{"sourceId":"firecrawl-search","title":"Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps","link":"https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html?m=1"},{"sourceId":"firecrawl-search","title":"CoSnitch: One-Click Data Exfiltration in Copilot Personal – Lab Space","link":"https://labs.cloudsecurityalliance.org/research/csa-research-note-microsoft-copilot-cosnitch-data-exfiltrati/"},{"sourceId":"firecrawl-search","title":"CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower","link":"https://www.varonis.com/blog/cosnitch"},{"sourceId":"firecrawl-search","title":"Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it – Computerworld","link":"https://www.computerworld.com/article/4211325/microsoft-finally-patches-critical-one-click-copilot-vulnerability-more-than-eight-months-after-learning-of-it.html"},{"sourceId":"firecrawl-search","title":"CoSnitch: When Copilot Starts Snitching | White Hat IT Security","link":"https://whitehat.eu/blog/copilot-cosnitch-cve-2026-24301/"},{"sourceId":"firecrawl-search","title":"THREAT ADVISORY CoSnitch Microsoft Copilot Personal Information Disclosure (prior to 8/18/26) August 26, 2026 - Blackswan Cybersecurity","link":"https://blackswan-cybersecurity.com/threat-advisory-cosnitch-microsoft-copilot-personal-information-disclosure-prior-to-8-18-26-august-26-2026/"}],"sourceItemIds":["3d6bf5654ef8341654fd6e9dcb1e8bc0e16340f5","7d240ec1ce10328eec189d9ac9d71f8934e087c4","88c311b12dca39cb1f3b0b3199c53298df43f929","caaef8850844edecd3f979e99db7f204dcb6e930","63b5cdc89d74e27f14b10b5ef2f2750091bad052","f13ca54df529e518f44aea4cf4044aef62c54bbf","45c6c7bca4a52086be9d6925d6e5ce0f460fa739","98f5ae0c8aa2b314f118b0e89a227d22bd254730","9488d88b539fdcdf376136de6aef8c45e84230f4","6d709108b6cc97d8f51e082e8ddea30d163115a4","3b0b1908edeb2bba5e34420675d6d8e77388c875","6c41295ea69aecfbe6ab68db2115c47a9442edc5","281cb7b17d30ffd49d642ad8d794970505d94d71"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-08-18T13:00:00.000Z","curatedAt":"2026-08-18T13:30:39.439Z","itemType":"incident","threatStatus":"patched","contentClass":"threat","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://blackswan-cybersecurity.com/threat-advisory-cosnitch-microsoft-copilot-personal-information-disclosure-prior-to-8-18-26-august-26-2026/","domain":"blackswan-cybersecurity.com","slug":null,"tier":"unknown","title":"THREAT ADVISORY CoSnitch Microsoft Copilot Personal Information Disclosure (prior to 8/18/26) August 26, 2026 - Blackswan Cybersecurity","pageTitle":"THREAT ADVISORY CoSnitch Microsoft Copilot Personal Information Disclosure (prior to 8/18/26) August 26, 2026 - Blackswan Cybersecurity"},{"role":"aggregator","url":"https://www.computerworld.com/article/4211325/microsoft-finally-patches-critical-one-click-copilot-vulnerability-more-than-eight-months-after-learning-of-it.html","domain":"computerworld.com","slug":null,"tier":"unknown","title":"Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it – Computerworld","pageTitle":"Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it – Computerworld"},{"role":"aggregator","url":"https://www.theregister.com/research/2026/08/18/copilot-tricked-into-telling-reseachers-how-to-hack-itself/5288857","domain":"theregister.com","slug":"theregister","tier":"known","title":"Copilot tricked into telling reseachers how to hack itself","pageTitle":"Copilot tricked into telling reseachers how to hack itself"},{"role":"aggregator","url":"https://www.cybersecurityintelligence.com/blog/one-click-attack-on-microsoft-copilot-9651.html","domain":"cybersecurityintelligence.com","slug":null,"tier":"unknown","title":"One Click Attack On Microsoft Copilot","pageTitle":"One Click Attack On Microsoft Copilot"},{"role":"aggregator","url":"https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/","domain":"arstechnica.com","slug":null,"tier":"unknown","title":"Microsoft Copilot reveals secret input that allowed it to be hacked - Ars Technica","pageTitle":"Microsoft Copilot reveals secret input that allowed it to be hacked - Ars Technica"},{"role":"aggregator","url":"https://whitehat.eu/blog/copilot-cosnitch-cve-2026-24301/","domain":"whitehat.eu","slug":null,"tier":"unknown","title":"CoSnitch: When Copilot Starts Snitching | White Hat IT Security","pageTitle":"CoSnitch: When Copilot Starts Snitching | White Hat IT Security"},{"role":"aggregator","url":"https://www.varonis.com/blog/cosnitch","domain":"varonis.com","slug":null,"tier":"unknown","sourceTrust":"trusted","title":"CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower","pageTitle":"CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower"},{"role":"aggregator","url":"https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html","domain":"thehackernews.com","slug":"thehackernews","tier":"known","title":"Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps","pageTitle":"Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps"},{"role":"aggregator","url":"https://www.darkreading.com/vulnerabilities-threats/cosnitch-attack-copilot-mapping-out-architecture","domain":"darkreading.com","slug":"darkreading","tier":"known","title":"'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture","pageTitle":"'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture"},{"role":"aggregator","url":"https://labs.cloudsecurityalliance.org/research/csa-research-note-microsoft-copilot-cosnitch-data-exfiltrati/","domain":"labs.cloudsecurityalliance.org","slug":null,"tier":"unknown","title":"CoSnitch: One-Click Data Exfiltration in Copilot Personal – Lab Space","pageTitle":"CoSnitch: One-Click Data Exfiltration in Copilot Personal – Lab Space"},{"role":"aggregator","url":"https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html?m=1","domain":"thehackernews.com","slug":"thehackernews","tier":"known","title":"Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps","pageTitle":"Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps"},{"role":"aggregator","url":"https://getaibook.com/news/cosnitch-exploit-leaks-copilot-data-via-hidden-url-parameter/","domain":"getaibook.com","slug":null,"tier":"unknown","title":"CoSnitch Exploit Leaks Copilot Data via Hidden URL Parameter | News","pageTitle":"CoSnitch Exploit Leaks Copilot Data via Hidden URL Parameter | News"},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24301","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-24301","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85046","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-85046","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9198","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-9198","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44756","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-44756","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72898","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-72898","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24299","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-24299","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32711","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2025-32711","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42824","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-42824","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32193","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-32193","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58231","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-58231","title":null},{"role":"vendor","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24301","domain":"msrc.microsoft.com","slug":"msrc","tier":"known","title":"CVE-2026-24301 - Microsoft Security Response Center"}]},{"id":"faf14165b17b1360f426dec403313a63c1151587","incidentId":"344d2ebe3d02bfeef30f5261ac085dad3eaa5613","title":"A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity","summary":"Palo Alto Networks' Unit 42 demonstrated that AWS AgentCore AI agents can be tricked via prompt injection into exfiltrating credentials in plaintext, despite the platform's encrypted secrets vault. In the demonstration, a malicious support ticket caused an AI agent to run code and send an authentication token to a test attacker; AWS reviewed the disclosure and closed it as informative, saying customers must restrict agent tools and access.","whyItMatters":"AWS AgentCore's encrypted vault does not prevent a prompt-injected agent from handing secrets to attackers, meaning defenders deploying agentic AI on AWS must lock down agent tools, scope key permissions, and monitor outbound traffic rather than trusting the vault alone.","threatTypeTags":["prompt-injection","data-exfiltration","credential-theft","tool-abuse"],"affectedTechTags":["ai-agents","aws-agentcore","llm"],"threatActor":null,"relevanceScore":0.95,"severityScore":0.6,"sources":[{"sourceId":"firecrawl-search","title":"AWS AgentCore AI agents can leak credentials despite vault | Cybernews","link":"https://cybernews.com/security/aws-agentcore-platform-credential-leak/"}],"sourceItemIds":["4679fe7aeffb557e73062aad581ca42d0f30e6c6"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-09-24T13:45:00.007Z","curatedAt":"2026-09-24T14:04:57.052Z","itemType":"research","threatStatus":"poc","contentClass":"threat","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://cybernews.com/security/aws-agentcore-platform-credential-leak/","domain":"cybernews.com","slug":null,"tier":"unknown","title":"AWS AgentCore AI agents can leak credentials despite vault | Cybernews","pageTitle":"AWS AgentCore AI agents can leak credentials despite vault | Cybernews"},{"role":"original","url":"https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/","domain":"unit42.paloaltonetworks.com","slug":"unit42","tier":"known","title":"A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity","pageTitle":"A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity","isPrimary":true}]},{"id":"f5932b82297c7ba8733fd50a84e34bd8d0351a71","incidentId":"4e6efae6c7dd7896492e36d8a8c684cc11c408b0","title":"Prompt Injection Hacking: Emerging Trade Secret, Employment, and Litigation Risks","summary":"A legal analysis from Kilpatrick Townsend (ktslaw.com) examines the emerging trade secret, employment, and litigation risks arising from prompt injection attacks against enterprise AI systems. The piece interprets how prompt injection — where attackers embed malicious instructions in content processed by LLMs and agents — creates novel legal exposure for organizations deploying AI, rather than presenting a new technical mechanism.","whyItMatters":"Prompt injection is treated here as a business and legal liability class, helping defenders and counsel understand how AI-security failures translate into trade secret loss, employment disputes, and litigation exposure.","threatTypeTags":["prompt-injection","data-exfiltration"],"affectedTechTags":["llm","ai-agents"],"threatActor":null,"relevanceScore":0.55,"severityScore":0.2,"sources":[{"sourceId":"firecrawl-search","title":"Multimodal Prompt Injection: Hidden Image & Document Attacks — Everyday on AI","link":"https://everydayonai.com/multimodal-prompt-injection"},{"sourceId":"firecrawl-search","title":"Visual prompt injections: are your multimodal controls keeping up?","link":"https://nhimg.org/community/agentic-ai-and-nhis/visual-prompt-injections-are-your-multimodal-controls-keeping-up/"},{"sourceId":"firecrawl-search","title":"Prompt Injection - The Attack That Turns Your AI Against You | Conosco","link":"https://conosco.com/industry-insights/prompt-injection-the-attack-that-turns-your-ai-against-you-conosco"},{"sourceId":"firecrawl-search","title":"Prompt Injection Attacks Are Now in Production: What We Learned from Real Breaches - Security Boulevard","link":"https://securityboulevard.com/2026/06/prompt-injection-attacks-are-now-in-production-what-we-learned-from-real-breaches/"},{"sourceId":"firecrawl-search","title":"7 Agentic AI Security Incidents Every Leader Should Know","link":"https://witness.ai/blog/agentic-ai-security-incidents/"},{"sourceId":"firecrawl-search","title":"What Is RAG Security? Risks, Architecture, and Enterprise Defense","link":"https://witness.ai/blog/rag-security/"},{"sourceId":"firecrawl-search","title":"5 runtime signals for catching a compromised AI agent | CSO Online","link":"https://www.csoonline.com/article/4184681/5-runtime-signals-for-catching-a-compromised-ai-agent.html"},{"sourceId":"firecrawl-search","title":"Prompt Injection & the Lethal Trifecta · collina.tech","link":"https://collina.tech/posts/prompt-injection-and-the-lethal-trifecta/"},{"sourceId":"firecrawl-search","title":"OWASP LLM Top 10 (2026): What Changed and What It Means for Your Security Program | infosec.qa","link":"https://infosec.qa/blog/owasp-llm-top-10-2026/"},{"sourceId":"firecrawl-search","title":"A Complete Walkthrough of TryHackMe’s Data Poisoning in RAG System | by Sudarshan Ajoy Sindhu | Jun, 2026 | Medium","link":"https://medium.com/@sudarshanajoysindhu/a-complete-walkthrough-of-tryhackmes-data-poisoning-in-rag-system-136aa9efb30b"},{"sourceId":"firecrawl-search","title":"Answers for the TryHackMe Data Poisoning in RAG Systems Room – Just another island on the internet","link":"https://simontaplin.net/2026/06/28/answers-for-the-tryhackme-data-poisoning-in-rag-systems-room/"},{"sourceId":"firecrawl-search","title":"What Is RAG Poisoning? Attacks, Risks & 2026 Defenses","link":"https://aithinkerlab.com/rag-poisoning-attacks-risks-defenses/"},{"sourceId":"firecrawl-search","title":"Prompt Injection Risks in Enterprise GenAI Tools | ServQual","link":"https://srql.com/knowledge/prompt-injection-risks-enterprise-genai-tools/"},{"sourceId":"firecrawl-search","title":"What Is a Prompt Injection Attack? Types, Examples, and Defenses | AI EdgeLabs","link":"https://edgelabs.ai/blog/what-is-prompt-injection-attack"},{"sourceId":"hn-search","title":"Bounding the Blast Radius: A Survey of Prompt-Injection Defenses for LLM Agents - Fabraix Research","link":"https://fabraix.com/blog/nobody-has-solved-prompt-injection"},{"sourceId":"firecrawl-search","title":"Prompt Injection Hacking: Emerging Trade Secret, Employment, and Litigation Risks","link":"https://ktslaw.com/en/insights/alert/2026/7/prompt%20injection%20hacking%20emerging%20trade%20secret%20employment%20and%20litigation%20risks"},{"sourceId":"firecrawl-search","title":"LLM01:2025 Prompt Injection - OWASP Gen AI Security Project","link":"https://genai.owasp.org/llmrisk/llm01-prompt-injection/"},{"sourceId":"firecrawl-search","title":"Prompt Injection: An Analysis of Recent LLM Security Incidents - NSFOCUS","link":"https://nsfocusglobal.com/prompt-word-injection-an-analysis-of-recent-llm-security-incidents/"},{"sourceId":"firecrawl-search","title":"How prompt injection puts your brand and AI workflows at risk","link":"https://searchengineland.com/prompt-injection-brand-ai-workflows-risk-483819"},{"sourceId":"firecrawl-search","title":"Finding the Confused Deputy in Your Own Agent: A Taxonomy and Hands-On Test | Amine Raji, PhD","link":"https://aminrj.com/posts/finding-confused-deputy-in-your-agent/"},{"sourceId":"firecrawl-search","title":"The Confused Deputy Has No Badge - Luminity Digital, Inc.","link":"https://luminitydigital.com/confused-deputy-agent-privilege-separation-identity/"},{"sourceId":"firecrawl-search","title":"Confused Deputy Problem: Why AI Agents Are Exposed to It - Pluto Security","link":"https://pluto.security/glossary/confused-deputy-problem/"},{"sourceId":"firecrawl-search","title":"What Is an MCP Server? How It Works and How to Secure It","link":"https://iternal.ai/what-is-an-mcp-server"},{"sourceId":"firecrawl-search","title":"MCP Security: Trust Boundaries, the Lethal Trifecta, and a Practical Scorecard | by Ankit Vashishta | Sep, 2026 | Medium","link":"https://medium.com/@ankit.vashishta/mcp-security-trust-boundaries-the-lethal-trifecta-and-a-practical-scorecard-f0ba742a87c2"},{"sourceId":"firecrawl-search","title":"The MCP Debrief - What's Actually Running on Your Endpoints - Pluto Security","link":"https://pluto.security/blog/the-mcp-debrief/"},{"sourceId":"firecrawl-search","title":"MCP Tool Poisoning: How It Works & How to Stop It | WSO2 API Content Hub","link":"https://wso2.com/api-platform/learn/mcp-tool-poisoning"},{"sourceId":"firecrawl-search","title":"MCP Security: Credentials, Rug Pulls, and Trust - Intro to Agents 101","link":"https://www.developersdigest.tech/courses/agents-101/mcp-security-credentials-rug-pulls-and-trust"},{"sourceId":"firecrawl-search","title":"Top 8 MCP security risks enterprises can't ignore | F5","link":"https://www.f5.com/company/blog/8-mcp-security-risks-every-enterprise-needs-to-know"},{"sourceId":"firecrawl-search","title":"Tool Poisoning on MCP Servers: The Attack Vector Nobody's Patching - DEV Community","link":"https://dev.to/numbpill3d/tool-poisoning-on-mcp-servers-the-attack-vector-nobodys-patching-3ai4"},{"sourceId":"firecrawl-search","title":"AI Agent Security Risks (And How to Actually Reduce Them)","link":"https://geotoolbox.ai/blog/ai-agent-security-risks"},{"sourceId":"firecrawl-search","title":"EchoLeakMicrosoft 365 Copilot Zero-Click Vulnerability — EchoLeak CVE-2025-32711 Full Case Study - YouTube","link":"https://m.youtube.com/watch?v=Np9cDrIQi-w"},{"sourceId":"hn-search","title":"AI Agent Goal Hijack: How Attackers Redirect an Agent's Goals, Planning, and Behavior","link":"https://darkmarc.substack.com/p/hijacking-ai-agents-how-an-agents"},{"sourceId":"firecrawl-search","title":"AI Agent Security Risks: OWASP Top 10, Translated | Amplence","link":"https://amplence.com/blog/ai-agent-security-risks"}],"sourceItemIds":["cc5e7be87b67945731e8ea0c5b2ae7e3c59acdc5","a3be1617e44df005832bba3e2b5583c1d3f76f02","60b8fa4862ccd1f333f45a1a458bf6141aacc623","8735f143268b47171a5014d023c03577c9cf04c3","e2f5247d5f56db205b36ffa168e804a2e958e2b1","f8db1b9d6521e430bf6716770589ea751f7e56e3","908b9426589c09e22a29ce5f67444c2cfa9bd51b","93c3b1244f0255dbf326b1bb28c682d2d25f2be1","5e14fe6eca0499455eef375418047eed9a82b8ad","9a6f8c8aeefc217068cf36b46573fd7746ebcf5c","5d337523c60f2405a4f720e4119f83db6eed85fa","c35d9bb2750431890d6adcd45fbeb0644a87ed6f","5d12c3771aa1d6349506364b61b4b3de891ca9b6","ae81489d43f8d7970296996836b21ed1f2ebcb26","91a468e83ca9021ea1878f7a4066e9e6d5580867","d5bf2be28de8e2f4e7189ad8fd5f7f25660f8e2f","9267e0c8ad5c77668e196f0037aaf2da7d8d5503","48ca08a41da75f5ee158340e6cfe82c8441c41b5","142dba2f8271716ba6196cc343c49600b4474a5c","16f8526fa02dec57446f6a1366ec6468fb772cda","ea1abfd79ee3425b8bf29e852b292a84fb43a9aa","9a264c2622244365a298672c84a3cade2ed0ba4f","bc3f5d02978f78e9742ce9dde235b49fc89c2929","b95fae2d63c686704651e8627f438b072702807a","fbcf86a3df61f4a140ed5b1f4ed4fb95646a4e9d","33bcdbf24ac88902a5ab9859da0fa296c8a1e616","556d6567362faa186497074c9044da9486c99bb7","0d55e52c944a3ef68023fedf7dcbe62806945668","47b2b7a51c4ddd0bfc54384e8d89aa45d893bb26","63ff191aac44119318d8f456b21124f5f76184bb","9fbf4bb22602f7f76ecf1aa0d725b85c93e07c91","c9eeb0c728a5d1015f553c43d56f46caeab33c1b","f9b8d8b81ad6e391dfd2b053f764c77abb91d04b"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-07-06T09:17:11.000Z","curatedAt":"2026-07-13T04:37:32.191Z","itemType":"analysis","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://www.f5.com/company/blog/8-mcp-security-risks-every-enterprise-needs-to-know","domain":"f5.com","slug":null,"tier":"unknown","title":"Top 8 MCP security risks enterprises can't ignore | F5","pageTitle":"Top 8 MCP security risks enterprises can't ignore | F5"},{"role":"aggregator","url":"https://searchengineland.com/prompt-injection-brand-ai-workflows-risk-483819","domain":"searchengineland.com","slug":null,"tier":"unknown","title":"How prompt injection puts your brand and AI workflows at risk","pageTitle":"How prompt injection puts your brand and AI workflows at risk"},{"role":"aggregator","url":"https://aminrj.com/posts/finding-confused-deputy-in-your-agent/","domain":"aminrj.com","slug":null,"tier":"unknown","title":"Finding the Confused Deputy in Your Own Agent: A Taxonomy and Hands-On Test | Amine Raji, PhD","pageTitle":"Finding the Confused Deputy in Your Own Agent: A Taxonomy and Hands-On Test | Amine Raji, PhD"},{"role":"aggregator","url":"https://wso2.com/api-platform/learn/mcp-tool-poisoning","domain":"wso2.com","slug":null,"tier":"unknown","title":"MCP Tool Poisoning: How It Works & How to Stop It | WSO2 API Content Hub","pageTitle":"MCP Tool Poisoning: How It Works & How to Stop It | WSO2 API Content Hub"},{"role":"aggregator","url":"https://dev.to/numbpill3d/tool-poisoning-on-mcp-servers-the-attack-vector-nobodys-patching-3ai4","domain":"dev.to","slug":"dev-to","tier":"known","title":"Tool Poisoning on MCP Servers: The Attack Vector Nobody's Patching - DEV Community","pageTitle":"Tool Poisoning on MCP Servers: The Attack Vector Nobody's Patching - DEV Community"},{"role":"aggregator","url":"https://nsfocusglobal.com/prompt-word-injection-an-analysis-of-recent-llm-security-incidents/","domain":"nsfocusglobal.com","slug":null,"tier":"unknown","title":"Prompt Injection: An Analysis of Recent LLM Security Incidents - NSFOCUS","pageTitle":"Prompt Injection: An Analysis of Recent LLM Security Incidents - NSFOCUS"},{"role":"aggregator","url":"https://www.developersdigest.tech/courses/agents-101/mcp-security-credentials-rug-pulls-and-trust","domain":"developersdigest.tech","slug":null,"tier":"unknown","title":"MCP Security: Credentials, Rug Pulls, and Trust - Intro to Agents 101","pageTitle":"MCP Security: Credentials, Rug Pulls, and Trust - Intro to Agents 101"},{"role":"aggregator","url":"https://srql.com/knowledge/prompt-injection-risks-enterprise-genai-tools/","domain":"srql.com","slug":null,"tier":"unknown","title":"Prompt Injection Risks in Enterprise GenAI Tools | ServQual","pageTitle":"Prompt Injection Risks in Enterprise GenAI Tools | ServQual"},{"role":"aggregator","url":"https://simontaplin.net/2026/06/28/answers-for-the-tryhackme-data-poisoning-in-rag-systems-room/","domain":"simontaplin.net","slug":null,"tier":"unknown","title":"Answers for the TryHackMe Data Poisoning in RAG Systems Room – Just another island on the internet","pageTitle":"Answers for the TryHackMe Data Poisoning in RAG Systems Room – Just another island on the internet"},{"role":"aggregator","url":"https://infosec.qa/blog/owasp-llm-top-10-2026/","domain":"infosec.qa","slug":null,"tier":"unknown","title":"OWASP LLM Top 10 (2026): What Changed and What It Means for Your Security Program | infosec.qa","pageTitle":"OWASP LLM Top 10 (2026): What Changed and What It Means for Your Security Program | infosec.qa"},{"role":"aggregator","url":"https://conosco.com/industry-insights/prompt-injection-the-attack-that-turns-your-ai-against-you-conosco","domain":"conosco.com","slug":null,"tier":"unknown","title":"Prompt Injection - The Attack That Turns Your AI Against You | Conosco","pageTitle":"Prompt Injection - The Attack That Turns Your AI Against You | Conosco"},{"role":"aggregator","url":"https://geotoolbox.ai/blog/ai-agent-security-risks","domain":"geotoolbox.ai","slug":null,"tier":"unknown","title":"AI Agent Security Risks (And How to Actually Reduce Them)","pageTitle":"AI Agent Security Risks (And How to Actually Reduce Them)"},{"role":"aggregator","url":"https://securityboulevard.com/2026/06/prompt-injection-attacks-are-now-in-production-what-we-learned-from-real-breaches/","domain":"securityboulevard.com","slug":null,"tier":"unknown","title":"Prompt Injection Attacks Are Now in Production: What We Learned from Real Breaches - Security Boulevard","pageTitle":"Prompt Injection Attacks Are Now in Production: What We Learned from Real Breaches - Security Boulevard"},{"role":"aggregator","url":"https://www.csoonline.com/article/4184681/5-runtime-signals-for-catching-a-compromised-ai-agent.html","domain":"csoonline.com","slug":null,"tier":"unknown","title":"5 runtime signals for catching a compromised AI agent | CSO Online","pageTitle":"5 runtime signals for catching a compromised AI agent | CSO Online"},{"role":"aggregator","url":"https://fabraix.com/blog/nobody-has-solved-prompt-injection","domain":"fabraix.com","slug":null,"tier":"unknown","title":"Bounding the Blast Radius: A Survey of Prompt-Injection Defenses for LLM Agents - Fabraix Research","pageTitle":"Bounding the Blast Radius: A Survey of Prompt-Injection Defenses for LLM Agents - Fabraix Research"},{"role":"aggregator","url":"https://genai.owasp.org/llmrisk/llm01-prompt-injection/","domain":"genai.owasp.org","slug":"owasp-genai","tier":"known","title":"LLM01:2025 Prompt Injection - OWASP Gen AI Security Project","pageTitle":"LLM01:2025 Prompt Injection - OWASP Gen AI Security Project"},{"role":"aggregator","url":"https://collina.tech/posts/prompt-injection-and-the-lethal-trifecta/","domain":"collina.tech","slug":null,"tier":"unknown","title":"Prompt Injection & the Lethal Trifecta · collina.tech","pageTitle":"Prompt Injection & the Lethal Trifecta · collina.tech"},{"role":"aggregator","url":"https://pluto.security/glossary/confused-deputy-problem/","domain":"pluto.security","slug":null,"tier":"unknown","title":"Confused Deputy Problem: Why AI Agents Are Exposed to It - Pluto Security","pageTitle":"Confused Deputy Problem: Why AI Agents Are Exposed to It - Pluto Security"},{"role":"aggregator","url":"https://medium.com/@sudarshanajoysindhu/a-complete-walkthrough-of-tryhackmes-data-poisoning-in-rag-system-136aa9efb30b","domain":"medium.com","slug":"medium","tier":"known","title":"A Complete Walkthrough of TryHackMe’s Data Poisoning in RAG System | by Sudarshan Ajoy Sindhu | Jun, 2026 | Medium","pageTitle":"A Complete Walkthrough of TryHackMe’s Data Poisoning in RAG System | by Sudarshan Ajoy Sindhu | Jun, 2026 | Medium"},{"role":"aggregator","url":"https://m.youtube.com/watch?v=Np9cDrIQi-w","domain":"m.youtube.com","slug":null,"tier":"unknown","title":"EchoLeakMicrosoft 365 Copilot Zero-Click Vulnerability — EchoLeak CVE-2025-32711 Full Case Study - YouTube","pageTitle":"EchoLeakMicrosoft 365 Copilot Zero-Click Vulnerability — EchoLeak CVE-2025-32711 Full Case Study - YouTube"},{"role":"aggregator","url":"https://nhimg.org/community/agentic-ai-and-nhis/visual-prompt-injections-are-your-multimodal-controls-keeping-up/","domain":"nhimg.org","slug":null,"tier":"unknown","title":"Visual prompt injections: are your multimodal controls keeping up?","pageTitle":"Visual prompt injections: are your multimodal controls keeping up?"},{"role":"aggregator","url":"https://edgelabs.ai/blog/what-is-prompt-injection-attack","domain":"edgelabs.ai","slug":null,"tier":"unknown","title":"What Is a Prompt Injection Attack? Types, Examples, and Defenses | AI EdgeLabs","pageTitle":"What Is a Prompt Injection Attack? Types, Examples, and Defenses | AI EdgeLabs"},{"role":"aggregator","url":"https://medium.com/@ankit.vashishta/mcp-security-trust-boundaries-the-lethal-trifecta-and-a-practical-scorecard-f0ba742a87c2","domain":"medium.com","slug":"medium","tier":"known","title":"MCP Security: Trust Boundaries, the Lethal Trifecta, and a Practical Scorecard | by Ankit Vashishta | Sep, 2026 | Medium","pageTitle":"MCP Security: Trust Boundaries, the Lethal Trifecta, and a Practical Scorecard | by Ankit Vashishta | Sep, 2026 | Medium"},{"role":"aggregator","url":"https://iternal.ai/what-is-an-mcp-server","domain":"iternal.ai","slug":null,"tier":"unknown","title":"What Is an MCP Server? How It Works and How to Secure It","pageTitle":"What Is an MCP Server? How It Works and How to Secure It"},{"role":"aggregator","url":"https://aithinkerlab.com/rag-poisoning-attacks-risks-defenses/","domain":"aithinkerlab.com","slug":null,"tier":"unknown","title":"What Is RAG Poisoning? Attacks, Risks & 2026 Defenses","pageTitle":"What Is RAG Poisoning? Attacks, Risks & 2026 Defenses"},{"role":"aggregator","url":"https://darkmarc.substack.com/p/hijacking-ai-agents-how-an-agents","domain":"darkmarc.substack.com","slug":null,"tier":"unknown","title":"AI Agent Goal Hijack: How Attackers Redirect an Agent's Goals, Planning, and Behavior","pageTitle":"AI Agent Goal Hijack: How Attackers Redirect an Agent's Goals, Planning, and Behavior"},{"role":"aggregator","url":"https://everydayonai.com/multimodal-prompt-injection","domain":"everydayonai.com","slug":null,"tier":"unknown","title":"Multimodal Prompt Injection: Hidden Image & Document Attacks — Everyday on AI","pageTitle":"Multimodal Prompt Injection: Hidden Image & Document Attacks — Everyday on AI"},{"role":"aggregator","url":"https://ktslaw.com/en/insights/alert/2026/7/prompt%20injection%20hacking%20emerging%20trade%20secret%20employment%20and%20litigation%20risks","domain":"ktslaw.com","slug":null,"tier":"unknown","title":"Prompt Injection Hacking: Emerging Trade Secret, Employment, and Litigation Risks","pageTitle":"Prompt Injection Hacking: Emerging Trade Secret, Employment, and Litigation Risks"},{"role":"aggregator","url":"https://witness.ai/blog/agentic-ai-security-incidents/","domain":"witness.ai","slug":null,"tier":"unknown","title":"7 Agentic AI Security Incidents Every Leader Should Know","pageTitle":"7 Agentic AI Security Incidents Every Leader Should Know"},{"role":"aggregator","url":"https://luminitydigital.com/confused-deputy-agent-privilege-separation-identity/","domain":"luminitydigital.com","slug":null,"tier":"unknown","title":"The Confused Deputy Has No Badge - Luminity Digital, Inc.","pageTitle":"The Confused Deputy Has No Badge - Luminity Digital, Inc."},{"role":"aggregator","url":"https://witness.ai/blog/rag-security/","domain":"witness.ai","slug":null,"tier":"unknown","title":"What Is RAG Security? Risks, Architecture, and Enterprise Defense","pageTitle":"What Is RAG Security? Risks, Architecture, and Enterprise Defense"},{"role":"aggregator","url":"https://amplence.com/blog/ai-agent-security-risks","domain":"amplence.com","slug":null,"tier":"unknown","title":"AI Agent Security Risks: OWASP Top 10, Translated | Amplence","pageTitle":"AI Agent Security Risks: OWASP Top 10, Translated | Amplence"},{"role":"aggregator","url":"https://pluto.security/blog/the-mcp-debrief/","domain":"pluto.security","slug":null,"tier":"unknown","title":"The MCP Debrief - What's Actually Running on Your Endpoints - Pluto Security","pageTitle":"The MCP Debrief - What's Actually Running on Your Endpoints - Pluto Security"},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21520","domain":"nvd.nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-21520","title":"CVE-2026-21520"},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32711","domain":"nvd.nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2025-32711","title":"CVE-2025-32711  NVD"},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53773","domain":"nvd.nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2025-53773","title":"CVE-2025-53773  NVD"},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54136","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2025-54136","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54135","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2025-54135","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-5184","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2024-5184","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59145","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2025-59145","title":null},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27825","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-27825","title":null}]},{"id":"5640105dbd0974d33d6f671351931ab8f5788674","incidentId":"8d1816996790b1124f0cae747b45dc58c7c2523d","title":"The lethal trifecta for AI agents: private data, untrusted content, and external communication","summary":"A course lesson explains the \"lethal trifecta\" concept coined by security researcher Simon Willison, describing how an AI agent that simultaneously holds access to private data, exposure to untrusted content, and an outbound communication channel can be tricked via prompt injection into exfiltrating sensitive data. The piece describes how removing any one of the three capabilities breaks the exfiltration circuit and references real-world exploits against Microsoft 365 Copilot, GitHub's MCP server, and GitLab Duo.","whyItMatters":"The lethal trifecta framework gives defenders a clear mental model for spotting when an AI agent's combination of capabilities creates a data-exfiltration risk from indirect prompt injection.","threatTypeTags":["prompt-injection","data-exfiltration","indirect-prompt-injection"],"affectedTechTags":["ai-agents","llm"],"threatActor":null,"relevanceScore":0.85,"severityScore":0.3,"sources":[{"sourceId":"firecrawl-search","title":"Data Exfiltration and the Lethal Trifecta - Intro to Agents 101","link":"https://www.developersdigest.tech/courses/agents-101/data-exfiltration-and-the-lethal-trifecta"}],"sourceItemIds":["735e95d9b679def7d9ae441aa3ccf9891108e080"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-09-24T13:45:00.007Z","curatedAt":"2026-09-24T14:04:31.122Z","itemType":"analysis","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://www.developersdigest.tech/courses/agents-101/data-exfiltration-and-the-lethal-trifecta","domain":"developersdigest.tech","slug":null,"tier":"unknown","title":"Data Exfiltration and the Lethal Trifecta - Intro to Agents 101","pageTitle":"Data Exfiltration and the Lethal Trifecta - Intro to Agents 101"},{"role":"original","url":"https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/","domain":"simonwillison.net","slug":"simonwillison","tier":"known","title":"The lethal trifecta for AI agents: private data, untrusted content, and external communication","pageTitle":"The lethal trifecta for AI agents: private data, untrusted content, and external communication","isPrimary":true}]},{"id":"9da02569184cfcb28a21f9b7666017d6b4ddc0f4","incidentId":"bb1956494ed9d861c2874b72d55877676bf808bf","title":"[2607.00422] KidnapRAG: A Black-Box Attack for Hijacking Reasoning in Agentic Retrieval-Augmented Generation Systems","summary":"KidnapRAG is a black-box attack presented as academic research that hijacks the reasoning process of agentic Retrieval-Augmented Generation (RAG) systems, steering their multi-step reasoning toward attacker-chosen conclusions without white-box access. The work targets the retrieval and reasoning surface that agentic RAG pipelines depend on, with accompanying code published on GitHub.","whyItMatters":"KidnapRAG shows that agentic RAG systems can have their reasoning chains hijacked via a practical black-box attack, expanding the poisoning threat surface defenders must account for in retrieval-grounded AI agents.","threatTypeTags":["rag-poisoning","context-poisoning","prompt-injection","reasoning-hijacking"],"affectedTechTags":["rag","ai-agents","llm"],"threatActor":null,"relevanceScore":0.92,"severityScore":0.5,"sources":[{"sourceId":"firecrawl-search","title":"[2607.00422] KidnapRAG: A Black-Box Attack for Hijacking Reasoning in Agentic Retrieval-Augmented Generation Systems","link":"https://arxiv.org/abs/2607.00422"},{"sourceId":"firecrawl-search","title":"[2609.21573] Micro-Collaborative Poisoning: A Distributed Attack on RAG Systems","link":"https://arxiv.org/abs/2609.21573"}],"sourceItemIds":["f316cb20d47824836985f1822e435891ad0cc5bb","0e0e9447d11fa8812acd7d0ff3be2e643ac3fa1a"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-07-21T05:15:00.008Z","curatedAt":"2026-07-21T05:36:01.514Z","itemType":"research","threatStatus":"unknown","contentClass":"research","toolPosture":null,"toolCategory":null,"references":[{"role":"original","url":"https://arxiv.org/abs/2607.00422","domain":"arxiv.org","slug":"arxiv","tier":"known","title":"KidnapRAG: A Black-Box Attack for Hijacking Reasoning in Agentic Retrieval-Augmented Generation Systems","pageTitle":"[2607.00422] KidnapRAG: A Black-Box Attack for Hijacking Reasoning in Agentic Retrieval-Augmented Generation Systems","isPrimary":true},{"role":"link","url":"https://github.com/chanwoochoi316/KidnapRAG","domain":"github.com","slug":"github","tier":"known","title":"KidnapRAG code repository"}]},{"id":"d8a7102ca2d83c0e9ec687cef0fc52eb2f6621a9","incidentId":"b3ab6262f899f29651ef0c2c16c5b55555bc4b71","title":"Two prompt injection paths into Rovo: one fixed (RovoBlast), one open. - Atlassian","summary":"Martin Runge's community write-up analyzes two prompt-injection techniques against Atlassian's Rovo AI assistant: RovoBlast (disclosed by Varonis Threat Labs at DEF CON 34), which abused a rovoChatPrompt URL parameter to inject instructions into an authenticated session and was fixed server-side by Atlassian on 8 July 2026; and an indirect prompt-injection method from PromptArmor that hides malicious instructions in content Rovo processes (Jira issues, Confluence, PDFs) and exfiltrates data via Markdown image and URL-retrieval requests. The second path is noted as still open, and disabling org-level web search does not stop it because the URL retrieval tool remains available.","whyItMatters":"Rovo's connectors reach Jira, Confluence, Bitbucket, Slack, Google Workspace and Microsoft 365, so an unpatched indirect prompt-injection exfiltration channel lets attackers silently siphon data a victim can access without any unusual user action.","threatTypeTags":["prompt-injection","indirect-prompt-injection","data-exfiltration","tool-abuse"],"affectedTechTags":["llm","ai-agents","rovo","copilot"],"threatActor":null,"relevanceScore":0.95,"severityScore":0.4,"sources":[{"sourceId":"firecrawl-search","title":"Two prompt injection paths into Rovo: one fixed (RovoBlast), one open. - Atlassian","link":"https://community.atlassian.com/forums/discussion/3282296/two-prompt-injection-paths-into-rovo-one-fixed-rovoblast-one-open"}],"sourceItemIds":["641545e33d5a7ac7ba0e97157e31d45aa496146a"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-09-24T13:45:00.007Z","curatedAt":"2026-09-24T14:04:57.032Z","itemType":"analysis","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://community.atlassian.com/forums/discussion/3282296/two-prompt-injection-paths-into-rovo-one-fixed-rovoblast-one-open","domain":"community.atlassian.com","slug":null,"tier":"unknown","title":"Two prompt injection paths into Rovo: one fixed (RovoBlast), one open. - Atlassian","pageTitle":"Two prompt injection paths into Rovo: one fixed (RovoBlast), one open. - Atlassian"}]},{"id":"c1be6b2dc0a1f2f231eba0bde5482e36bd28de47","incidentId":"42e0d563805c64ef22a95f75fe31a6db8aef5a0d","title":"Poisoning the Context: Securing RAG Pipelines Against Knowledge Injection Attacks - DEV Community","summary":"An educational write-up and accompanying lab walkthrough explain RAG (Retrieval-Augmented Generation) data poisoning, where an attacker edits an unauthenticated shared knowledge base (e.g. a company wiki, SharePoint doc, or vector database) so the LLM retrieves and repeats attacker-controlled false 'policies' such as instructing employees to wire money to a fraudulent account. The material demonstrates the attack against a deliberately vulnerable pipeline and discusses securing RAG pipelines against such knowledge-injection attacks.","whyItMatters":"RAG data poisoning lets an attacker who can write to a knowledge base turn a trusted AI assistant into a vector for fraud and misinformation without ever touching the model itself, a risk any enterprise deploying RAG must mitigate.","threatTypeTags":["memory-injection","data-poisoning","rag-poisoning","indirect-prompt-injection"],"affectedTechTags":["rag","llm","vector-store"],"threatActor":null,"relevanceScore":0.78,"severityScore":0.3,"sources":[{"sourceId":"firecrawl-search","title":"RAG Data Poisoning Attack Walkthrough | LLM Security (Vulnerable Lab) - YouTube","link":"https://www.youtube.com/watch?v=YCRa9JNM2M4"},{"sourceId":"firecrawl-search","title":"Medium","link":"https://ai.plainenglish.io/your-rag-can-be-hacked-without-touching-your-llm-understanding-data-poisoning-806e8e1ec392"},{"sourceId":"firecrawl-search","title":"Knowledge Poisoning in RAG: Attacking AI Through Its Knowledge Base - DEV Community","link":"https://dev.to/rijultp/knowledge-poisoning-in-rag-attacking-ai-through-its-knowledge-base-3gp1"},{"sourceId":"firecrawl-search","title":"Poisoning the Context: Securing RAG Pipelines Against Knowledge Injection Attacks - DEV Community","link":"https://dev.to/tamizuddin/poisoning-the-context-securing-rag-pipelines-against-knowledge-injection-attacks-184h"}],"sourceItemIds":["595f5e061394b980f292971068341ab77d4583e5","8af0ca39b494fd342988c921f872efb006096c68","8c24280e1a067637fa32249f3a0761dc6111e6ae","aac0f12c9dd621d0e600089ac3ec94efae927e4f"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-09-08T11:45:00.007Z","curatedAt":"2026-09-08T12:03:39.041Z","itemType":"analysis","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://www.youtube.com/watch?v=YCRa9JNM2M4","domain":"youtube.com","slug":"youtube","tier":"known","title":"RAG Data Poisoning Attack Walkthrough | LLM Security (Vulnerable Lab) - YouTube","pageTitle":"RAG Data Poisoning Attack Walkthrough | LLM Security (Vulnerable Lab) - YouTube"},{"role":"aggregator","url":"https://ai.plainenglish.io/your-rag-can-be-hacked-without-touching-your-llm-understanding-data-poisoning-806e8e1ec392","domain":"ai.plainenglish.io","slug":null,"tier":"unknown","title":"Medium","pageTitle":"Medium"},{"role":"aggregator","url":"https://dev.to/rijultp/knowledge-poisoning-in-rag-attacking-ai-through-its-knowledge-base-3gp1","domain":"dev.to","slug":"dev-to","tier":"known","title":"Knowledge Poisoning in RAG: Attacking AI Through Its Knowledge Base - DEV Community","pageTitle":"Knowledge Poisoning in RAG: Attacking AI Through Its Knowledge Base - DEV Community"},{"role":"aggregator","url":"https://dev.to/tamizuddin/poisoning-the-context-securing-rag-pipelines-against-knowledge-injection-attacks-184h","domain":"dev.to","slug":"dev-to","tier":"known","title":"Poisoning the Context: Securing RAG Pipelines Against Knowledge Injection Attacks - DEV Community","pageTitle":"Poisoning the Context: Securing RAG Pipelines Against Knowledge Injection Attacks - DEV Community"}]},{"id":"b9e552f236e94dbfc7ba2c503aed127622f88b45","incidentId":"acbd2ca77370cacd85fb9f0b6ce98c4d41d254e3","title":"WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus Poisoning | Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1","summary":"WARP (presented in the abstract as SilentRetrieval) is a two-stage retrieval-corpus poisoning attack against RAG systems that inserts adversarial yet fluent documents using Coordinated Beam Search and Context-Adaptive Trigger Generation. Evaluated on Natural Questions and MS MARCO, it achieves up to 84.6% HR@10 and 57.5% ASR-LLM while retaining near-benign perplexity and transferring to unseen retrievers including ColBERT and commercial embedding models.","whyItMatters":"WARP demonstrates that a single poisoned document per query can reliably hijack RAG outputs while evading fluency-based detection, showing corpus integrity is a practical attack surface defenders must protect.","threatTypeTags":["data-poisoning","supply-chain","backdoor","corpus-poisoning"],"affectedTechTags":["rag","llm"],"threatActor":null,"relevanceScore":0.9,"severityScore":0.5,"sources":[{"sourceId":"firecrawl-search","title":"When Context Bites: Detecting RAG Poisoning via Document-Level Attention Collapse | Proceedings of the 49th International ACM SIGIR Conference on Research and Development in Information Retrieval","link":"https://dl.acm.org/doi/10.1145/3805712.3809904"},{"sourceId":"firecrawl-search","title":"SilentRetrieval: Hijacking Retrieval-Augmented Generation via Semantically-Preserving Adversarial Data Poisoning | Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2","link":"https://dl.acm.org/doi/10.1145/3770855.3818186"},{"sourceId":"firecrawl-search","title":"WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus Poisoning | Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1","link":"https://dl.acm.org/doi/abs/10.1145/3770854.3780227"}],"sourceItemIds":["bcd16bf5fbff6a496982f92e74069ec76807d966","47aac4975b0aea50786c8b0dd605b11b4feebba3","57ba7b350f73341bc14c708624ed2ffc85a3b791"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-07-15T04:30:00.008Z","curatedAt":"2026-07-15T05:06:48.080Z","itemType":"research","threatStatus":"unknown","contentClass":"research","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://dl.acm.org/doi/10.1145/3770855.3818186","domain":"dl.acm.org","slug":null,"tier":"unknown","title":"SilentRetrieval: Hijacking Retrieval-Augmented Generation via Semantically-Preserving Adversarial Data Poisoning | Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2","pageTitle":"SilentRetrieval: Hijacking Retrieval-Augmented Generation via Semantically-Preserving Adversarial Data Poisoning | Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2"},{"role":"aggregator","url":"https://dl.acm.org/doi/abs/10.1145/3770854.3780227","domain":"dl.acm.org","slug":null,"tier":"unknown","title":"WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus Poisoning | Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1","pageTitle":"WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus Poisoning | Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1"},{"role":"aggregator","url":"https://dl.acm.org/doi/10.1145/3805712.3809904","domain":"dl.acm.org","slug":null,"tier":"unknown","title":"When Context Bites: Detecting RAG Poisoning via Document-Level Attention Collapse | Proceedings of the 49th International ACM SIGIR Conference on Research and Development in Information Retrieval","pageTitle":"When Context Bites: Detecting RAG Poisoning via Document-Level Attention Collapse | Proceedings of the 49th International ACM SIGIR Conference on Research and Development in Information Retrieval"}]},{"id":"6d4681a6e775f71397306b26aa704a2fa14476ef","incidentId":"48bea01fbf561e5f82e0f67da54de8bd0127ecdc","title":"AI Agent Memory Poisoning: Persistent Agent Attacks","summary":"An explainer on agent memory poisoning argues that, unlike a one-shot prompt injection, a single malicious write to an agent's persistent memory is retrieved and executed across future sessions against users who never saw the attack. It synthesizes red-team research including AgentPoison (backdooring agent memory/RAG stores), MINJA (query-only memory injection), a systematic MPBench study, and MemGhost stealth email-based injection, then recommends architectural defenses: authorizing writes outside the model, provenance stamping, trust-weighted retrieval, and quarantining new writes.","whyItMatters":"Agent memory poisoning turns a personalization feature into a persistent, cross-session — and potentially cross-tenant — instruction channel that existing prompt-injection defenses do not cover, forcing defenders to treat memory writes as a security boundary.","threatTypeTags":["memory-injection","memory-poisoning","indirect-prompt-injection","data-exfiltration","supply-chain"],"affectedTechTags":["ai-agents","llm","rag","mem0","vector-store"],"threatActor":null,"relevanceScore":0.94,"severityScore":0.4,"sources":[{"sourceId":"firecrawl-search","title":"Memory poisoning in AI agents: are your controls keeping up?","link":"https://nhimg.org/community/agentic-ai-and-nhis/memory-poisoning-in-ai-agents-are-your-controls-keeping-up/"},{"sourceId":"firecrawl-search","title":"How Memory Poisoning in Agentic AI Works","link":"https://witness.ai/blog/memory-poisoning-agentic-ai/"},{"sourceId":"firecrawl-search","title":"AI Memory Security: Best Practices and Implementation","link":"https://mem0.ai/blog/ai-memory-security-best-practices"},{"sourceId":"firecrawl-search","title":"AI Agent Memory Poisoning: Persistent Agent Attacks","link":"https://cybersecpentesting.com/blog/ai-agent-memory-poisoning.html"},{"sourceId":"firecrawl-search","title":"Agent Memory Poisoning: The Persistent Attack (2026) — AppScale Blog","link":"https://appscale.blog/en/blog/agent-memory-poisoning-persistent-adversarial-writes-provenance-quarantine-2026"},{"sourceId":"firecrawl-search","title":"AI Agent Memory Security Guide | GS Consulting","link":"https://gsconsultingllc.com/insights/ai-agent-memory-security"}],"sourceItemIds":["4e7d056305ca4eb659c57caacbeb419c48651f3c","1d0a133de9efc8dbf411657ec5779ec6bebd611b","164e7d344b69f429a82445319de0488113e33532","860822f98eeacb600c8c2d3fd694a9aa1d664558","0b385b8d5300680850936ddd1fbd08b56f9007de","e746dcb2e6a06d67043344c493ab314e90f688b1"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-07-15T04:30:00.008Z","curatedAt":"2026-07-15T05:07:15.784Z","itemType":"analysis","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://appscale.blog/en/blog/agent-memory-poisoning-persistent-adversarial-writes-provenance-quarantine-2026","domain":"appscale.blog","slug":null,"tier":"unknown","title":"Agent Memory Poisoning: The Persistent Attack (2026) — AppScale Blog","pageTitle":"Agent Memory Poisoning: The Persistent Attack (2026) — AppScale Blog"},{"role":"aggregator","url":"https://mem0.ai/blog/ai-memory-security-best-practices","domain":"mem0.ai","slug":null,"tier":"unknown","title":"AI Memory Security: Best Practices and Implementation","pageTitle":"AI Memory Security: Best Practices and Implementation"},{"role":"aggregator","url":"https://witness.ai/blog/memory-poisoning-agentic-ai/","domain":"witness.ai","slug":null,"tier":"unknown","title":"How Memory Poisoning in Agentic AI Works","pageTitle":"How Memory Poisoning in Agentic AI Works"},{"role":"aggregator","url":"https://nhimg.org/community/agentic-ai-and-nhis/memory-poisoning-in-ai-agents-are-your-controls-keeping-up/","domain":"nhimg.org","slug":null,"tier":"unknown","title":"Memory poisoning in AI agents: are your controls keeping up?","pageTitle":"Memory poisoning in AI agents: are your controls keeping up?"},{"role":"aggregator","url":"https://cybersecpentesting.com/blog/ai-agent-memory-poisoning.html","domain":"cybersecpentesting.com","slug":null,"tier":"unknown","title":"AI Agent Memory Poisoning: Persistent Agent Attacks","pageTitle":"AI Agent Memory Poisoning: Persistent Agent Attacks"},{"role":"aggregator","url":"https://gsconsultingllc.com/insights/ai-agent-memory-security","domain":"gsconsultingllc.com","slug":null,"tier":"unknown","title":"AI Agent Memory Security Guide | GS Consulting","pageTitle":"AI Agent Memory Security Guide | GS Consulting"},{"role":"original","url":"https://arxiv.org/abs/2407.12784","domain":"arxiv.org","slug":"arxiv","tier":"known","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","pageTitle":"[2407.12784] AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases"},{"role":"original","url":"https://arxiv.org/abs/2503.03704","domain":"arxiv.org","slug":"arxiv","tier":"known","title":"Memory Injection Attacks on LLM Agents via Query-Only Interaction (MINJA)","pageTitle":"[2503.03704] Memory Injection Attacks on LLM Agents via Query-Only Interaction"},{"role":"original","url":"https://arxiv.org/html/2606.04329v1","domain":"arxiv.org","slug":"arxiv","tier":"known","title":"From Untrusted Input to Trusted Memory: A Systematic Study of Memory Poisoning Attacks in LLM Agents","pageTitle":"From Untrusted Input to Trusted Memory: A Systematic Study of Memory Poisoning Attacks in LLM Agents"},{"role":"original","url":"https://arxiv.org/abs/2607.05189","domain":"arxiv.org","slug":"arxiv","tier":"known","title":"When Claws Remember but Do Not Tell: Stealthy Memory Injection in Persistent Personal Agents (MemGhost)","pageTitle":"[2607.05189] When Claws Remember but Do Not Tell: Stealthy Memory Injection in Persistent Personal Agents"}]},{"id":"5c72fcda308a63728b106133b246c2659acfb4c2","incidentId":"a5392c7e315fec7727fed95d4b6d8215b44cbbf3","title":"Your AI Agent Remembers Everything. An Attacker Only Needs It to Remember One Thing. | by Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA] | Sep, 2026 | Medium","summary":"A Medium write-up by the persona 'Aeon Flex / NEON MAXIMA' explains how memory poisoning can turn persistent AI agents into 'sleeper cells,' citing academic research claiming a ~95% success rate and framing RAG pipelines as the widest attack surface. The piece walks through the attack mechanism against persistent agent memory along with proposed defenses.","whyItMatters":"Memory poisoning of persistent AI agents lets an attacker plant a single durable instruction that resurfaces across future sessions, and RAG ingestion pipelines are a common ingress point defenders must harden.","threatTypeTags":["memory-injection","memory-poisoning","prompt-injection","supply-chain"],"affectedTechTags":["ai-agents","rag","llm"],"threatActor":null,"relevanceScore":0.85,"severityScore":0.3,"sources":[{"sourceId":"firecrawl-search","title":"Your AI Agent Remembers Everything. An Attacker Only Needs It to Remember One Thing. | by Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA] | Sep, 2026 | Medium","link":"https://medium.com/@neonmaxima/your-ai-agent-remembers-everything-an-attacker-only-needs-it-to-remember-one-thing-dc0a085ad83c"}],"sourceItemIds":["3b8fb8dc8bb91be19a70bdaf8bc58f0d469c4f09"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-09-24T13:45:00.007Z","curatedAt":"2026-09-24T14:05:39.276Z","itemType":"analysis","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://medium.com/@neonmaxima/your-ai-agent-remembers-everything-an-attacker-only-needs-it-to-remember-one-thing-dc0a085ad83c","domain":"medium.com","slug":"medium","tier":"known","title":"Your AI Agent Remembers Everything. An Attacker Only Needs It to Remember One Thing. | by Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA] | Sep, 2026 | Medium","pageTitle":"Your AI Agent Remembers Everything. An Attacker Only Needs It to Remember One Thing. | by Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA] | Sep, 2026 | Medium"}]},{"id":"215fc63adb47e0d20e77e7d05ff26ec0b89c2590","incidentId":"7656041d56aaa0b68de7800070017e1da38a2e50","title":"Agentforce Security: What Salesforce Covers and What You Own","summary":"An explainer titled \"Agentforce Security: What Salesforce Covers and What You Own\" discusses the shared-responsibility model for securing Salesforce's Agentforce AI agent platform, referencing related Agentforce agent risks such as the ForcedLeak research. The retrievable content is largely a cookie-consent banner, and the page's linked references include crafted prompts attempting to make AI summarizers vouch for the publisher's authority.","whyItMatters":"Agentforce and similar enterprise AI-agent platforms introduce a shared-responsibility security model where misconfiguration and indirect prompt injection can expose customer data, making it important for defenders to understand which controls they own.","threatTypeTags":["prompt-injection","data-exfiltration"],"affectedTechTags":["ai-agents","salesforce-agentforce","llm"],"threatActor":null,"relevanceScore":0.55,"severityScore":0.2,"sources":[{"sourceId":"firecrawl-search","title":"Agentforce Security: What Salesforce Covers and What You Own","link":"https://sombrainc.com/blog/agentforce-security"}],"sourceItemIds":["0c6af3fda511ee1ecd5024766c0a9c4bb8c77ccd"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-09-24T13:45:00.007Z","curatedAt":"2026-09-24T14:05:39.293Z","itemType":"analysis","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://sombrainc.com/blog/agentforce-security","domain":"sombrainc.com","slug":null,"tier":"unknown","title":"Agentforce Security: What Salesforce Covers and What You Own","pageTitle":"Agentforce Security: What Salesforce Covers and What You Own"},{"role":"link","url":"https://noma.security/blog/forcedleak-agent-risks-exposed-in-salesforce-agentforce","domain":"noma.security","slug":null,"tier":"unknown","title":"ForcedLeak: Agent Risks Exposed in Salesforce Agentforce"}]},{"id":"6716eccbf6d24b6222f07d45b434f696aec330fe","incidentId":"a21198db2334c66a7a1cba4b6cfcde3e5a578ee0","title":"Model Denial of Service in LLM Deployments · LLM Security Review","summary":"\"Model Denial of Service in LLM Deployments\" synthesizes the OWASP 2026 Top 10 'unbounded consumption' risk, describing denial-of-wallet via leaked API keys, agent tool fan-out from malicious linked content, reasoning-loop exhaustion, context accumulation, and model extraction, alongside referenced research such as the OverThink slowdown attack on reasoning LLMs (arXiv:2502.02542). Mitigations discussed include hard spending/token caps, agent step and loop limits, repetitive-loop detection, sandboxing, and least-privilege controls.","whyItMatters":"Unbounded consumption lets attackers inflate an enterprise's compute costs or extract models without triggering downtime, so defenders deploying LLM agents need cost caps, loop detection, and least-privilege controls to avoid runaway 'denial-of-wallet' losses.","threatTypeTags":["model-denial-of-service","denial-of-wallet","unbounded-consumption","resource-exhaustion","prompt-injection","tool-abuse"],"affectedTechTags":["llm","ai-agents","rag"],"threatActor":null,"relevanceScore":0.85,"severityScore":0.4,"sources":[{"sourceId":"firecrawl-search","title":"How to Avoid Runaway LLM Costs","link":"https://hiflylabs.com/blog/2026/7/16/cap-llm-api-use-avoid-runaway-llm-costs"},{"sourceId":"firecrawl-search","title":"Denial of Wallet: When the Bill Is the LLM Attack — AppScale Blog","link":"https://appscale.blog/en/blog/denial-of-wallet-llm-cost-exhaustion-attack-defence-architecture-2026"},{"sourceId":"firecrawl-search","title":"Model Denial of Service in LLM Deployments · LLM Security Review","link":"https://llmsecurityreview.com/posts/model-denial-of-service-in-llm-deployments"},{"sourceId":"firecrawl-search","title":"LLM Denial of Wallet Does Not Need to Overwhelm Anything | DeepInspect","link":"https://www.deepinspect.ai/blog/llm-denial-of-wallet"},{"sourceId":"darkreading","title":"How AI Agents Can Trigger Runaway Costs for Enterprises","link":"https://www.darkreading.com/application-security/how-ai-agents-can-trigger-runaway-costs"},{"sourceId":"firecrawl-search","title":"Denial-of-Wallet Attacks Drive Excessive AI Agent Token and Tool Consumption | Mallory","link":"https://mallory.ai/stories/01a0c90a-05f5-7a62-beea-70420b6584a8"},{"sourceId":"firecrawl-search","title":"How AI Agents Can Trigger Runaway Costs for Enterprises","link":"https://daily.dev/posts/how-ai-agents-can-trigger-runaway-costs-for-enterprises-1nrrxscyo"}],"sourceItemIds":["de9374576a997b243746cfb39a1ac36559df6d0a","10986d69a0ea25e64d28bcace84f44452e0b7a64","9a4fc060b7c3a8123b99ea3f069e299810188033","f51482ed6fb038b8a482596560976ebe48c5baf7","87efe792caaa27cbd9d46d91155fe63be5a5c9b0","a99b96f699c1692b62134706e3f499f47c8a1ccb","9cd4f1d801a6a1314a0fb897bfd6e3cf0ada55ff","0d8190bc486bb4028e1a38d5708bf18cb49b469d"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-07-26T05:45:00.008Z","curatedAt":"2026-07-26T06:06:26.496Z","itemType":"analysis","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://daily.dev/posts/how-ai-agents-can-trigger-runaway-costs-for-enterprises-1nrrxscyo","domain":"daily.dev","slug":null,"tier":"unknown","title":"How AI Agents Can Trigger Runaway Costs for Enterprises","pageTitle":"How AI Agents Can Trigger Runaway Costs for Enterprises"},{"role":"aggregator","url":"https://appscale.blog/en/blog/denial-of-wallet-llm-cost-exhaustion-attack-defence-architecture-2026","domain":"appscale.blog","slug":null,"tier":"unknown","title":"Denial of Wallet: When the Bill Is the LLM Attack — AppScale Blog","pageTitle":"Denial of Wallet: When the Bill Is the LLM Attack — AppScale Blog"},{"role":"aggregator","url":"https://www.darkreading.com/application-security/how-ai-agents-can-trigger-runaway-costs","domain":"darkreading.com","slug":"darkreading","tier":"known","title":"How AI Agents Can Trigger Runaway Costs for Enterprises","pageTitle":"How AI Agents Can Trigger Runaway Costs for Enterprises"},{"role":"aggregator","url":"https://llmsecurityreview.com/posts/model-denial-of-service-in-llm-deployments","domain":"llmsecurityreview.com","slug":null,"tier":"unknown","title":"Model Denial of Service in LLM Deployments · LLM Security Review","pageTitle":"Model Denial of Service in LLM Deployments · LLM Security Review"},{"role":"aggregator","url":"https://mallory.ai/stories/01a0c90a-05f5-7a62-beea-70420b6584a8","domain":"mallory.ai","slug":null,"tier":"unknown","title":"Denial-of-Wallet Attacks Drive Excessive AI Agent Token and Tool Consumption | Mallory","pageTitle":"Denial-of-Wallet Attacks Drive Excessive AI Agent Token and Tool Consumption | Mallory"},{"role":"aggregator","url":"https://hiflylabs.com/blog/2026/7/16/cap-llm-api-use-avoid-runaway-llm-costs","domain":"hiflylabs.com","slug":null,"tier":"unknown","title":"How to Avoid Runaway LLM Costs","pageTitle":"How to Avoid Runaway LLM Costs"},{"role":"aggregator","url":"https://www.deepinspect.ai/blog/llm-denial-of-wallet","domain":"deepinspect.ai","slug":null,"tier":"unknown","title":"LLM Denial of Wallet Does Not Need to Overwhelm Anything | DeepInspect","pageTitle":"LLM Denial of Wallet Does Not Need to Overwhelm Anything | DeepInspect"},{"role":"link","url":"https://genai.owasp.org/llmrisk/llm102025-unbounded-consumption/","domain":"genai.owasp.org","slug":"owasp-genai","tier":"known","title":"OWASP LLM10:2025 Unbounded Consumption"},{"role":"original","url":"https://arxiv.org/abs/2502.02542","domain":"arxiv.org","slug":"arxiv","tier":"known","title":"OverThink: Slowdown Attacks on Reasoning LLMs","pageTitle":"[2502.02542] OverThink: Slowdown Attacks on Reasoning LLMs"}]},{"id":"c30addec8136364e3a5d4eb6ee9b05fb85b65793","incidentId":"f83b1be1975dabf07fecd7d1bf0aa4971e6daf6d","title":"Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools | VentureBeat","summary":"Slopsquatting is a software supply-chain attack in which attackers register package names that AI coding agents predictably hallucinate, so an agent running in auto mode installs and executes the attacker's malicious package. Cited research reports that ~19.7% of AI-recommended packages don't exist, with 43-58% of hallucinated names repeated consistently, and academic work (adversarial/HalluSquatting) demonstrates hallucination rates up to 85-100% that transfer across models and can achieve remote tool and code execution.","whyItMatters":"Slopsquatting turns the predictable hallucinations of AI coding assistants into a reliable, scalable delivery vector for malware, meaning developers who let agents auto-install dependencies can be compromised before a human ever reviews the code.","threatTypeTags":["supply-chain","package-hallucination","slopsquatting","tool-abuse","remote-code-execution"],"affectedTechTags":["llm","ai-agents","ai-coding-assistants","npm","pypi","composer"],"threatActor":null,"relevanceScore":0.9,"severityScore":0.5,"sources":[{"sourceId":"firecrawl-search","title":"Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools | VentureBeat","link":"https://venturebeat.com/security/forget-typosquatting-slopsquatting-is-the-software-supply-chain-threat-created-by-ai-coding-tools"},{"sourceId":"firecrawl-search","title":"What Is Slopsquatting? (+ the HalluSquatting Attack)","link":"https://www.cybedefend.com/en/blog/what-is-slopsquatting"},{"sourceId":"firecrawl-search","title":"Slopsquatting: The Supply Chain Attack AI Made Possible","link":"https://www.linkedin.com/pulse/slopsquatting-supply-chain-attack-ai-made-possible-amitav-roy-nlwrf"},{"sourceId":"firecrawl-search","title":"Security Tip: Have You Heard Of Slopsquatting?","link":"https://securinglaravel.com/security-tip-have-you-heard-of-slopsquatting/"},{"sourceId":"firecrawl-search","title":"Slopsquatting: AI Package Hallucination Rates 2026","link":"https://particula.tech/blog/slopsquatting-package-hallucination-rates-supply-chain-2026"},{"sourceId":"bleepingcomputer","title":"Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack","link":"https://www.bleepingcomputer.com/news/security/slopsquatting-phantom-domains-and-hallusquatting-are-the-same-ai-attack/"},{"sourceId":"firecrawl-search","title":"What Is Slopsquatting in AI Generated Code • Vinish.Dev","link":"https://vinish.dev/what-is-slopsquatting-in-ai-generated-code"},{"sourceId":"firecrawl-search","title":"Slopsquatting at Agent Speed: What Hallucinated Resolution Actually Breaks | AI Security Now","link":"https://aisecurity-now.com/analysis/ai-slop/"},{"sourceId":"firecrawl-search","title":"Slopsquatting explained: When AI code turns malicious | TechTarget","link":"https://www.techtarget.com/it-strategy/feature/Slopsquatting-explained-When-AI-code-turns-malicious"},{"sourceId":"firecrawl-search","title":"AI Package Typosquatting: How LLM Hallucinations Are Poisoning the Software Supply Chain","link":"https://secnora.com/blog/ai-package-typosquatting-llm-supply-chain/"}],"sourceItemIds":["7b483ace7f06f82c7069cba08dcca4234c3cd30f","b8fe0cc4d96d614ae62cd88f6ece572f64ece576","3e959bf98de69d14863e3f0b80083e9613b3620c","1881493ffd6f70bacd8404c2548572c13fc7d26c","b9cfd8bf0220b58bd4544cf5c2793ca7f298a542","c7481740bbfdd692c548e3706e07f00738ad4993","2883f39c05fe14683b0e2d970e15a272c5e5021c","e9c3890a11b6a3f51bd471830596ac5581a17aaf","85c353f33cc8e40b9a6c74f22c536e187f07e46f","5731717061a83f94b34f5fa32e8cd9c7b635029b","a336309e4a61a101f45638d78c67a1ca1753fe75"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-07-16T04:30:00.018Z","curatedAt":"2026-07-16T05:07:30.187Z","itemType":"analysis","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://securinglaravel.com/security-tip-have-you-heard-of-slopsquatting/","domain":"securinglaravel.com","slug":null,"tier":"unknown","title":"Security Tip: Have You Heard Of Slopsquatting?","pageTitle":"Security Tip: Have You Heard Of Slopsquatting?"},{"role":"aggregator","url":"https://www.bleepingcomputer.com/news/security/slopsquatting-phantom-domains-and-hallusquatting-are-the-same-ai-attack/","domain":"bleepingcomputer.com","slug":"bleepingcomputer","tier":"known","title":"Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack","pageTitle":"Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack"},{"role":"aggregator","url":"https://www.linkedin.com/pulse/slopsquatting-supply-chain-attack-ai-made-possible-amitav-roy-nlwrf","domain":"linkedin.com","slug":"linkedin","tier":"known","title":"Slopsquatting: The Supply Chain Attack AI Made Possible","pageTitle":"Slopsquatting: The Supply Chain Attack AI Made Possible"},{"role":"aggregator","url":"https://www.techtarget.com/it-strategy/feature/Slopsquatting-explained-When-AI-code-turns-malicious","domain":"techtarget.com","slug":null,"tier":"unknown","title":"Slopsquatting explained: When AI code turns malicious | TechTarget","pageTitle":"Slopsquatting explained: When AI code turns malicious | TechTarget"},{"role":"aggregator","url":"https://venturebeat.com/security/forget-typosquatting-slopsquatting-is-the-software-supply-chain-threat-created-by-ai-coding-tools","domain":"venturebeat.com","slug":null,"tier":"unknown","title":"Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools | VentureBeat","pageTitle":"Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools | VentureBeat"},{"role":"aggregator","url":"https://aisecurity-now.com/analysis/ai-slop/","domain":"aisecurity-now.com","slug":null,"tier":"unknown","title":"Slopsquatting at Agent Speed: What Hallucinated Resolution Actually Breaks | AI Security Now","pageTitle":"Slopsquatting at Agent Speed: What Hallucinated Resolution Actually Breaks | AI Security Now"},{"role":"aggregator","url":"https://secnora.com/blog/ai-package-typosquatting-llm-supply-chain/","domain":"secnora.com","slug":null,"tier":"unknown","title":"AI Package Typosquatting: How LLM Hallucinations Are Poisoning the Software Supply Chain","pageTitle":"AI Package Typosquatting: How LLM Hallucinations Are Poisoning the Software Supply Chain"},{"role":"aggregator","url":"https://www.cybedefend.com/en/blog/what-is-slopsquatting","domain":"cybedefend.com","slug":null,"tier":"unknown","title":"What Is Slopsquatting? (+ the HalluSquatting Attack)","pageTitle":"What Is Slopsquatting? (+ the HalluSquatting Attack)"},{"role":"aggregator","url":"https://particula.tech/blog/slopsquatting-package-hallucination-rates-supply-chain-2026","domain":"particula.tech","slug":null,"tier":"unknown","title":"Slopsquatting: AI Package Hallucination Rates 2026","pageTitle":"Slopsquatting: AI Package Hallucination Rates 2026"},{"role":"aggregator","url":"https://vinish.dev/what-is-slopsquatting-in-ai-generated-code","domain":"vinish.dev","slug":null,"tier":"unknown","title":"What Is Slopsquatting in AI Generated Code • Vinish.Dev","pageTitle":"What Is Slopsquatting in AI Generated Code • Vinish.Dev"},{"role":"original","url":"https://arxiv.org/abs/2607.07433","domain":"arxiv.org","slug":"arxiv","tier":"known","title":"Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting","pageTitle":"[2607.07433] Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting"},{"role":"original","url":"https://arxiv.org/abs/2506.12995","domain":"arxiv.org","slug":"arxiv","tier":"known","title":"Open Source, Open Threats? Investigating Security Challenges in Open-Source Software","pageTitle":"[2506.12995] Open Source, Open Threats? Investigating Security Challenges in Open-Source Software"}]},{"id":"c9602411218080ad0689620e5e86d5a4e59518ec","incidentId":"6a925c69d629d6d443ec831b68d343f98eb2b110","title":"The Price of Safety: Benign-Case Utility and Token Overhead of Memory-Poisoning Defenses in LLM Agents","summary":"A research paper by Pritom Bhowmik measures the benign-case utility and token overhead of four memory-poisoning defenses for LLM agents (input sanitization, provenance checking, LLM-based anomaly detection, and retrieval-time reranking) on entirely benign LoCoMo traffic. Write-time defenses show no resolvable utility cost, while the read-time reranker lowers core accuracy by 4.4 points and quarantines legitimate memories on 33.6% of adjudicated items at 2.7% token overhead. Code is available at github.com/pritom02bh/memdefense.","whyItMatters":"Memory-poisoning defenses run on all agent traffic while attacks are rare, so quantifying their cost on benign interactions helps defenders decide whether a defense degrades ordinary agent operation more than it protects it.","threatTypeTags":["memory-injection","memory-poisoning"],"affectedTechTags":["llm","ai-agents"],"threatActor":null,"relevanceScore":0.85,"severityScore":0.2,"sources":[{"sourceId":"firecrawl-search","title":"The Price of Safety: Benign-Case Utility and Token Overhead of Memory-Poisoning Defenses in LLM Agents","link":"https://arxiv.org/html/2609.22818v1"}],"sourceItemIds":["28e610b9315a776b4f3076d9d2b7478163ab85ad"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-09-24T13:45:00.007Z","curatedAt":"2026-09-24T14:05:55.003Z","itemType":"research","threatStatus":"unknown","contentClass":"research","toolPosture":null,"toolCategory":null,"references":[{"role":"original","url":"https://arxiv.org/html/2609.22818v1","domain":"arxiv.org","slug":"arxiv","tier":"known","title":"The Price of Safety: Benign-Case Utility and Token Overhead of Memory-Poisoning Defenses in LLM Agents","pageTitle":"The Price of Safety: Benign-Case Utility and Token Overhead of Memory-Poisoning Defenses in LLM Agents","isPrimary":true},{"role":"link","url":"https://github.com/pritom02bh/memdefense","domain":"github.com","slug":"github","tier":"known","title":"memdefense code repository"}]},{"id":"98bf83b86d19aad83f7297224d0f44ab92281cdd","incidentId":"03d77398cce7ec4ea63f51cf80c6977793ee68ae","title":"How attackers weaponize generative AI through data poisoning and manipulation | Barracuda Networks Blog","summary":"Barracuda's blog explains how attackers weaponize generative AI through two broad attack categories: data poisoning, which corrupts the training data an LLM relies on (citing researchers who found 100 poisoned models uploaded to Hugging Face), and data manipulation. The piece is an educational overview of how these attacks undermine the reliability, accuracy, and integrity of LLM-based systems.","whyItMatters":"Data poisoning and manipulation of LLM training data threaten the integrity of increasingly essential AI systems, and defenders benefit from understanding these attack classes and examples like poisoned models on public model hubs.","threatTypeTags":["data-poisoning","supply-chain","model-manipulation"],"affectedTechTags":["llm","generative-ai"],"threatActor":null,"relevanceScore":0.72,"severityScore":0.3,"sources":[{"sourceId":"firecrawl-search","title":"How attackers weaponize generative AI through data poisoning and manipulation | Barracuda Networks Blog","link":"https://blog.barracuda.com/2024/04/03/generative-ai-data-poisoning-manipulation"}],"sourceItemIds":["31f4e5630ea6be8ef6dfa967f4df533e92146087"],"publishedAt":"2026-09-24T13:45:00.007Z","firstReportedAt":"2026-09-24T13:45:00.007Z","curatedAt":"2026-09-24T14:06:09.700Z","itemType":"analysis","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://blog.barracuda.com/2024/04/03/generative-ai-data-poisoning-manipulation","domain":"blog.barracuda.com","slug":null,"tier":"unknown","title":"How attackers weaponize generative AI through data poisoning and manipulation | Barracuda Networks Blog","pageTitle":"How attackers weaponize generative AI through data poisoning and manipulation | Barracuda Networks Blog"},{"role":"link","url":"https://www.darkreading.com/application-security/hugging-face-ai-platform-100-malicious-code-execution-models","domain":"darkreading.com","slug":"darkreading","tier":"known","title":"Hugging Face AI Platform: 100 Malicious Code-Execution Models"}]}],"total":1212,"limit":20,"offset":0}