logo

Block CISO: We red-teamed our own AI agent to run an infostealer on an employee laptop

ID: ed3dc2a5-ff0e-5835-abad-435218f0b1a5

STIX ID: report--ed3dc2a5-ff0e-5835-abad-435218f0b1a5

Feed Name: The Register (Security)

Threat Score
55/100

Date Published: 2026-01-12

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Block's CISO describes how the company red-teamed its open-source AI agent Goose and discovered that attackers could poison reusable "recipes" (workflows) — using phishing and invisible Unicode prompt injections — to trick developers into downloading and executing an information‑stealing malware. In response, Block added recipe install warnings, desktop alerts for suspicious Unicode, removal of invisible characters, detection improvements, and is experimenting with adversarial AI checks to mitigate prompt-injection risks and enforce least-privilege access for agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.