Hackers Abuse SEO Poisoning and Hidden HTML to Trick AI Agents Into Following Malicious Instructions
ID: 1a7e5ba3-01d4-554b-ba84-8eb82b147a60
STIX ID: report--1a7e5ba3-01d4-554b-ba84-8eb82b147a60
Feed Name: cybersecurityNews.com
Zscaler researchers observed two campaigns abusing search-engine optimization and hidden JSON-LD to perform indirect prompt injection against AI agents: one impersonated a fake Python package docs page to prompt a $3 fraudulent license payment, and the other used a typosquatted DeBank domain to trick models into treating the site as authoritative. The report includes multiple malicious domains, associated GitHub repositories, an Ethereum wallet address used to collect payments, and recommends layered security controls to detect hidden injection patterns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
