The Wire.Tracking threats to Agents 312 raw → 45 curated · updated 27 Jun 2026

Incident · curated 27 Jun 2026

Prompt Injection in RAG Agentic Systems – Ulad Khomich – Software Engineer from SpiralScout

First reported 8 Jun 2026 · 18d ago

Coverage timeline

8 Jun 2026

Single-source incident — first reported, latest, and curated coincide.

It shows how a company's own internal knowledge base becomes an attack surface, where any indexed document can carry instructions that an AI assistant will execute, expanding the trust boundary to a supply-chain problem.

A technical write-up explaining how indirect prompt injection works in RAG agentic systems, where retrieved documents (Confluence pages, Jira tickets, HR docs) land in the model's context with no trust boundary, allowing a single poisoned document to manipulate agent behavior and exfiltrate sensitive data. Includes a demonstration repository and production mitigation discussion.

Why it matters

It shows how a company's own internal knowledge base becomes an attack surface, where any indexed document can carry instructions that an AI assistant will execute, expanding the trust boundary to a supply-chain problem.

Curated from sources around the web.
Permalinks stay valid even if an incident is later merged.   Feed · Search · API docs · RSS