New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
Ask an AI agent to summarize the reviews on a product page and a single planted review can make it click Buy Now instead Ask a coding assistant to apply a maintainers fix from a GitHub thread and a fake comment can make it run a strangers command on your computer Neither trick hijacks the agents task Each one just corrupts the facts it trusts and lets it carry on with the job you