AI Agents Are Being Hijacked in the Wild: 22 Attack Techniques Now Documented
Unit 42 researchers catch indirect prompt injection attacks actively weaponizing AI agents on live websites, from forced transactions to data exfiltration
Category
Unit 42 researchers catch indirect prompt injection attacks actively weaponizing AI agents on live websites, from forced transactions to data exfiltration
A single HTTP request can own your AI workflow server. CVE-2026-33017 shows why authentication shouldn't be optional.
The AI agent that couldn't stop getting hacked now has 4 critical and 52 high-severity flaws. Here's the latest wave of March 2026 CVEs.
A rogue AI agent triggers Sev 1 at Meta, agentic browsers leak passwords, and researchers prove AI can autonomously jailbreak other AI with 97% success.
A Sev 1 security incident at Meta after an internal AI agent posted unauthorized advice that led to a two-hour data exposure. Sound familiar?
The open-source AI agent with 135,000+ GitHub stars has become the center of 2026's first major AI security crisis
Every major AI chatbot now trains on your conversations by default. Here's what each platform collects and step-by-step instructions to protect yourself.
A self-propagating malware campaign steals developer credentials via malicious VS Code extensions, then force-pushes cryptocurrency-stealing code into legitimate Python projects.
Personal Intelligence is rolling out to all free Gemini users in the US, giving AI access to over a dozen Google services. Privacy experts warn the convenience comes with significant risks.
World launches AgentKit, a tool that lets AI shopping bots prove a human backs them - by linking to biometric data from the controversial Orb device
Zenity Labs discloses critical flaws in agentic browsers like Perplexity Comet. A zero-click attack can steal local files and passwords without user interaction.
Leaked internal email shows Ring's lost dog feature is the foundation for broader AI surveillance. Congress demands answers as partnership with Flock Safety collapses.
Three teenagers have filed a federal class action against Elon Musk's xAI, alleging Grok was used to create child sexual abuse material from their photos. It's the first lawsuit where minors are plaintiffs.
The largest copyright settlement in history closes March 30. If your book was pirated by AI, here's what you need to know and how to file a claim.
The QuitGPT movement, 1.5 million user exodus, and the deal that split the AI industry over autonomous weapons and mass surveillance
As AI-generated political ads proliferate in the 2026 midterms, YouTube expands its likeness detection technology to civic leaders, but critics question whether the tool can keep pace with rapidly improving fakes
From Chat & Ask AI's 300 million exposed messages to widespread hardcoded secrets, security researchers reveal a systemic failure across AI applications
One in five packages in OpenClaw's ClawHub registry contain malicious code. The first coordinated attack on AI agent infrastructure reveals systemic vulnerabilities that enterprises are only beginning to understand.
A busy week for AI vulnerabilities: video-based RCE, chat injection leading to full system compromise, and research showing AI agents autonomously bypass security controls.
A $200/month Mac mini running an always-on AI agent with full file system access raises serious privacy questions - especially after Perplexity's recent security track record.
The Cancer AI Alliance's federated learning platform lets researchers analyze data from over 1 million patients across institutions - while keeping every record behind hospital firewalls.
New research shows AI can link your Reddit burner account to your real identity for under $4. The era of casual online pseudonymity may be ending.
New research from ETH Zurich and Anthropic shows AI can identify pseudonymous online accounts with 67% accuracy at just $1-4 per person - and there's no easy fix.
One in four Americans received an AI voice clone scam call last year. 77% of those who engaged lost money. Here's what actually works to protect your family.