Research · curated 27 Jun 2026

Pwning Agentic AI Part I: Your AI Agent Is Already Compromised | Trend Micro (US)

Coverage timeline

11 Jun 2026trendmicro.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

Agents wired into databases and internal tools can be weaponized through hidden instructions to exfiltrate sensitive data while staying within granted privileges, bypassing traditional network and access controls.

Trend Micro's TrendAI Research describes a new agentic-AI exploitation pattern they call return-to-tool (RTT) exploits, where embedded instructions in benign-looking untrusted input cause an AI agent to invoke its authorized tools to perform attacker-intended actions such as exfiltrating production database credentials. The research notes a vulnerable PostgreSQL MCP server image pulled over 100,000 times from Docker Hub as a realistic exposure vector.