AI Agent Faces New Security Risks
AI Agent has become the focus of new security research. Two separate research teams recently uncovered serious weaknesses. As a result, attackers may trick the agent into running commands or exposing sensitive data.
Researchers demonstrated different attack methods. However, both attacks reached the same goal. Attackers gained influence over the agent through trusted inputs. Therefore, the agent performed actions that users never intended.
One issue has already been fixed in newer software versions. However, another problem involves how AI agents make decisions. Therefore, technical patches alone may not solve every risk.
Hidden Commands Inside Shared Content
Researchers discovered that attackers could hide instructions inside ordinary messages. For example, shared contacts, vCards, and location pins could contain malicious commands. These commands remained invisible to victims. The problem occurred when the AI agent processed messaging content. Instead of separating trusted and untrusted information, the agent combined everything together. Therefore, the language model could not distinguish real data from hidden instructions.
Attackers took advantage of this design flaw. For example, they placed commands inside contact names. The commands appeared harmless to users. However, the AI agent interpreted them as instructions.
In testing, hidden prompts successfully convinced the agent to download and run scripts. Therefore, attackers could execute unauthorized actions remotely. Researchers noted that image-based attacks were less effective. However, message-based attacks worked surprisingly well.
Why the Flaw Was Dangerous
The threat became more serious because memory features were enabled by default. As a result, malicious instructions could remain active for longer periods. Therefore, one shared item could affect multiple future interactions.
Researchers warned that widely shared content could spread the attack further. For example, a poisoned contact card could reach many users. Consequently, multiple AI agents could process the same hidden commands.
The affected platform released a security update. The fix moved contact information into a separate untrusted area. Therefore, the AI model no longer treats those fields as instructions.
However, researchers found similar weaknesses in other AI assistants. Therefore, the issue extends beyond a single platform. The broader challenge remains unresolved across the industry.
Phishing Emails Can Fool AI Agents
A second research team focused on social engineering attacks. Instead of hiding commands, they used normal-looking emails. As a result, the AI agent willingly shared sensitive information.
Researchers built a test environment filled with realistic business data. They then sent phishing emails to the AI agent. However, the emails appeared routine and believable. One message claimed to come from a team leader. It requested access credentials during a fake emergency. Therefore, the AI agent forwarded sensitive information without proper verification.
Another email requested customer records for a business presentation. The request sounded normal and urgent. Consequently, the AI agent exported customer data and sent it outside the organization.
AI Agents Struggle With Social Judgement
Researchers found an important pattern during testing. The AI agent often recognized technical threats. For example, it detected suspicious websites and fake login pages. However, the agent struggled with human-focused deception. Therefore, phishing emails remained highly effective. The AI agent prioritized being helpful over being cautious.
Researchers observed similar results across different language models. Although some systems behaved more carefully, both still fell for convincing social requests. Therefore, the underlying problem affects many AI-powered assistants.
The findings highlight a major challenge. AI agents can process information quickly. However, they often lack the intuition humans use when judging unusual requests.
Additional Weaknesses Found
Researchers also reviewed other communication integrations. During the analysis, they discovered several related vulnerabilities. These flaws affected multiple messaging channels. The issue involved user verification methods. Instead of checking unique identifiers, the system relied on display names. Therefore, attackers could impersonate approved users by changing their names.
Once impersonation succeeded, attackers gained influence over the AI agent. Consequently, they could steer tasks and requests. The affected flaws have since been patched.
Despite these fixes, researchers remain concerned. AI agents often receive broad access to files, emails, and communication tools. Therefore, a single mistake can create significant security risks.
Why AI Agent Security Requires New Thinking
Researchers describe these attacks as part of a larger problem. AI agents can read private data, process outside content, and send information elsewhere. Therefore, attackers only need to compromise one of those steps.
The challenge grows because AI agents are designed to help users. As a result, they naturally trust incoming requests. However, that same behavior creates opportunities for abuse.
Researchers compare AI agents to junior employees with powerful system access. They can complete tasks efficiently. However, they may fail to recognize suspicious situations. Therefore, organizations should not treat AI agents as security tools. Instead, they should view them as automated assistants that require oversight and controls.
How to Prevent AI Agent Abuse
Organizations should update AI platforms immediately whenever security fixes become available. In addition, strong access controls should limit what AI agents can read, modify, and share. Managed Detection and Response services can help monitor suspicious AI-driven activity and identify unusual behavior quickly.
Furthermore, regular security assessments and vulnerability management programs can uncover hidden weaknesses before attackers exploit them. Human approval should also remain mandatory for high-risk actions, such as sharing credentials, exporting sensitive data, or transferring critical business information.
Sleep well, we got you covered.

