News Article · Jun 8, 2026 at 8:44 AM
3 min read 0
Member
AI Agents With Hands Create New Attack Surface as Phishing Kits and Prompt Injection Threats Multiply
Security #AI agents #prompt injection #phishing #Palo Alto Networks #Google Gemini #Kali365 #DriveSurge

AI Agents With Hands Create New Attack Surface as Phishing Kits and Prompt Injection Threats Multiply

Security researchers highlight three emerging threats: AI agents that can manipulate APIs and databases, a prompt injection flaw in Google Gemini, and the Kali365 phishing kit expanding beyond Microsoft 365.

Listen to this article 3 min

Security researchers are tracking a convergence of threats as AI agents gain the ability to execute actions, phishing kits expand their targets, and prompt injection flaws emerge in voice assistants. Palo Alto Networks on Wednesday warned that autonomous AI agents with access to APIs, databases, and outbound channels create a new attack surface that traditional guardrails cannot protect.

Palo Alto Networks calls this shift "agents with hands", models that can hit APIs, query databases, and execute tasks without human oversight. The company's Prisma AIRS product sits between agent traffic and tool calls, inspecting payloads rather than just natural-language prompts. The threat model involves three combined elements: private data access, exposure to untrusted content, and an outbound channel. None is dangerous alone, but together they describe how data can leave a network quietly.

Multi-agent setups compound the problem because east-west traffic between agents means a hallucination in one agent can ripple through the entire chain. Standardized connectors like MCP describe how an agent talks to a tool but say nothing about whether the request is legitimate. Named attacks include memory poisoning, where instructions are planted that an agent executes weeks later, and "confused deputy" attacks that trick a read-only agent into writing. Rugpulls involve a tool that works reliably for months before quietly siphoning data.

Amazon Bedrock Guardrails and similar text filters work for governance and content safety but will not catch SQL injection buried inside a tool payload, according to Palo Alto Networks. Prisma AIRS takes a second pass, watching payloads and killing connections when an agent demands admin privileges.

Separately, researchers at Dark Reading reported a prompt injection flaw in Google Gemini's voice assistant that lets attackers hide malicious commands in notifications, enabling social engineering. The flaw could trick users into executing actions they did not intend.

Meanwhile, the Kali365 phishing-as-a-service platform, previously flagged by the FBI for targeting Microsoft 365, has expanded to target AWS, Okta, and Russian platforms. The kit relies on device code phishing, a technique that tricks users into entering codes on attacker-controlled devices.

In another development, a malicious traffic distribution system called DriveSurge has hijacked thousands of websites to redirect visitors to ClickFix and FakeUpdate attacks. The operation uses a traffic distribution system to redirect visitors of trusted websites to malware delivery pages.

Security experts say the combination of AI agent capabilities, expanding phishing kits, and prompt injection flaws creates a complex threat environment. Organizations need to assume the perimeter is already inside and watch what agents do rather than only what they say.

Fact check

  • Palo Alto Networks introduced Prisma AIRS to inspect tool calls and network flows for AI agent traffic.

    reported · source

  • A prompt injection flaw in Google Gemini's voice assistant lets attackers hide malicious commands in notifications.

    reported · source

  • The Kali365 phishing kit now targets AWS, Okta, and Russian platforms in addition to Microsoft 365.

    reported · source

  • DriveSurge hijacks thousands of websites for ClickFix and FakeUpdate attacks.

    reported · source

Source reporting (20)

0 Comments

No comments yet

Be the first to share your thoughts on this article.