logo

IBM's AI agent Bob easily duped to run malware, researchers show

ID: c0223188-bea3-5c6f-8d20-35acc16e1481

STIX ID: report--c0223188-bea3-5c6f-8d20-35acc16e1481

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-01-07

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Researchers from PromptArmor found that IBM's Bob AI development agent (CLI and IDE) is vulnerable to prompt-injection and command-chaining flaws that can be abused to execute arbitrary shell scripts (leading to malware or ransomware) and to an IDE rendering/CSP bug that could enable zero-click data exfiltration; these issues demonstrate that allow-lists and simple user-approval flows can be bypassed, and IBM has been informed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.