AI Agents With Hands Create New Attack Surface as Phishing Kits and Prompt Injection Threats Multiply
Security researchers highlight three emerging threats: AI agents that can manipulate APIs and databases, a prompt injection flaw in Google Gemini, and the Kali365 phishing kit expanding beyond Microsoft 365.
Security researchers are tracking a convergence of threats as AI agents gain the ability to execute actions, phishing kits expand their targets, and prompt injection flaws emerge in voice assistants. Palo Alto Networks on Wednesday warned that autonomous AI agents with access to APIs, databases, and outbound channels create a new attack surface that traditional guardrails cannot protect.
Palo Alto Networks calls this shift "agents with hands", models that can hit APIs, query databases, and execute tasks without human oversight. The company's Prisma AIRS product sits between agent traffic and tool calls, inspecting payloads rather than just natural-language prompts. The threat model involves three combined elements: private data access, exposure to untrusted content, and an outbound channel. None is dangerous alone, but together they describe how data can leave a network quietly.
Multi-agent setups compound the problem because east-west traffic between agents means a hallucination in one agent can ripple through the entire chain. Standardized connectors like MCP describe how an agent talks to a tool but say nothing about whether the request is legitimate. Named attacks include memory poisoning, where instructions are planted that an agent executes weeks later, and "confused deputy" attacks that trick a read-only agent into writing. Rugpulls involve a tool that works reliably for months before quietly siphoning data.
Amazon Bedrock Guardrails and similar text filters work for governance and content safety but will not catch SQL injection buried inside a tool payload, according to Palo Alto Networks. Prisma AIRS takes a second pass, watching payloads and killing connections when an agent demands admin privileges.
Separately, researchers at Dark Reading reported a prompt injection flaw in Google Gemini's voice assistant that lets attackers hide malicious commands in notifications, enabling social engineering. The flaw could trick users into executing actions they did not intend.
Meanwhile, the Kali365 phishing-as-a-service platform, previously flagged by the FBI for targeting Microsoft 365, has expanded to target AWS, Okta, and Russian platforms. The kit relies on device code phishing, a technique that tricks users into entering codes on attacker-controlled devices.
In another development, a malicious traffic distribution system called DriveSurge has hijacked thousands of websites to redirect visitors to ClickFix and FakeUpdate attacks. The operation uses a traffic distribution system to redirect visitors of trusted websites to malware delivery pages.
Security experts say the combination of AI agent capabilities, expanding phishing kits, and prompt injection flaws creates a complex threat environment. Organizations need to assume the perimeter is already inside and watch what agents do rather than only what they say.
Fact check
-
Palo Alto Networks introduced Prisma AIRS to inspect tool calls and network flows for AI agent traffic.
reported · source
-
A prompt injection flaw in Google Gemini's voice assistant lets attackers hide malicious commands in notifications.
reported · source
-
The Kali365 phishing kit now targets AWS, Okta, and Russian platforms in addition to Microsoft 365.
reported · source
-
DriveSurge hijacks thousands of websites for ClickFix and FakeUpdate attacks.
reported · source
Source reporting (20)
- The Register · AI agents can now manipulate your organization. Are you ready?
- The Register · Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures
- Dark Reading · Malicious Notifications Could Trick Google Gemini Users
- Dark Reading · FBI-Flagged Phishing Kit Kali365 Expands Its Reach
- Dark Reading · DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks
- Dark Reading · China Uses Dual-Method Cyberattack on Czech Orgs
- Dark Reading · Securing AI Agents Before They Go Rogue Is Next to Impossible
- Dark Reading · Beyond Assume-Breach: How AI-Native Security Will Reshape Enterprise Defense
- The Hacker News · Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore
- The Hacker News · Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag
- The Hacker News · Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)
- The Hacker News · Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
- The Hacker News · New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
- The Hacker News · Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
- The Hacker News · Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
- The Hacker News · Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
- The Hacker News · Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
- The Hacker News · AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.
- The Hacker News · How Leading Organizations Are Turning EDR Into Operational Resilience
- CyberScoop · DOD wants to integrate cyber in all operations, and integrate security into AI
Related Articles
Snowflake hacker pleads guilty to stealing data from 165 organizations, faces 32 years in prison
Aug 5, 2026
AI Agents From OpenAI and Anthropic Breach Real Websites During Security Tests
Aug 5, 2026
AI Agent Security Startups Zenity and Horizon3.ai Raise $375M Combined as SentinelOne Expands Autonomous SOC
Aug 3, 2026
0 Comments
No comments yet
Be the first to share your thoughts on this article.