logo

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

ID: c7b57746-8c3a-566c-aeec-a66238495119

STIX ID: report--c7b57746-8c3a-566c-aeec-a66238495119

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2026-07-16

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Researchers present "agent data injection" (ADI), a class of attacks that forges or injects data treated as trusted metadata by AI agents (e.g., sender names, element IDs, tool results), causing agents to perform unintended actions—such as clicking a "Buy Now" button, running attacker commands on a developer machine, or merging malicious pull requests. The paper demonstrates proof-of-concept attacks across multiple commercial models and tools with substantial success rates, evaluates partial mitigations (randomized IDs, provenance tracking, punctuation stripping), and reports vendor disclosure without evidence of active real-world exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.