logo

New “Lies-in-the-Loop” Attack Undermines AI Safety Dialogs

ID: d35a4db2-face-57e9-877c-568007e4b60d

STIX ID: report--d35a4db2-face-57e9-877c-568007e4b60d

Feed Name: Infosecurity Magazine (News)

Threat Score
60/100

Date Published: 2025-12-17

Date Updated: 2026-04-22

...
...

Checkmarx researchers disclosed a technique named "Lies-in-the-Loop (LITL)" that manipulates Human-in-the-Loop approval dialogs in AI agents so benign-looking confirmations trigger arbitrary code execution; demonstrations targeted Claude Code and Microsoft Copilot Chat, vendors acknowledged reports but did not fully remediate, and the researchers recommend layered mitigations including Markdown sanitization, clearer dialog UI, safe OS APIs, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.