hacker-news · Crawled Jul 16, 2026

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

Read original article ↗

AI Summary

Researchers have identified a new class of attack called Agent Data Injection (ADI), which exploits how AI agents parse structured data by injecting malicious input disguised as trusted data elements like sender names or button IDs. Unlike traditional prompt injection, ADI corrupts underlying facts the agent trusts, enabling actions such as unintended clicks or execution of attacker-controlled commands. The attack affects multiple AI models including GPT-5, Claude, and Gemini, with success rates up to 50% despite existing defenses. No real-world exploitation has been reported, but proof-of-concept demonstrations show high effectiveness across web and coding agents.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.