logo

Radware Discloses ZombieAgent Technique to Compromise AI Agents

ID: 1b0123e5-417a-5129-b615-d60677270292

STIX ID: report--1b0123e5-417a-5129-b615-d60677270292

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-01-09

Date Updated: 2026-04-22

Author: Michael Vizard

...
...

Radware disclosed a zero-click indirect prompt injection (ZombieAgent) vulnerability in OpenAI's Deep Research agent that allows attackers to implant malicious rules into an agent's memory, creating persistent, hidden actions executed within the cloud (no endpoint logs or network traffic). Although Radware has not observed active exploitation, the technique could enable long-term data exfiltration or unauthorized actions across connected tools, and existing guardrails and monitoring approaches may be insufficient to detect or prevent such compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.