Tool Hijacking: The 2024 Papers That Predicted Agent Attacks

By November 2024, AI-agent security research had already documented the attack class that production incidents would later make infamous. InjecAgent (March 2024, ACL Findings) benchmarked 1,054 indirect-injection scenarios across 30 agents, finding ReAct-prompted GPT-4 attacked successfully roughly a quarter of the time. Breaking Agents (July 2024) demonstrated malfunction amplification through agentic loops. Together with 2023’s foundational indirect-prompt-injection work, they mapped how tools, descriptions, and fetched content become command channels. This survey walks the papers, the hijack taxonomy, and the controls that predate the incidents.

Continue ReadingTool Hijacking: The 2024 Papers That Predicted Agent Attacks

Google AI Overviews: Prompt Injection Hits the Homepage of the Internet

When Google rolled AI Overviews into US search in May 2024, satirical sources got quoted as fact at national scale — glue on pizza, rocks as vitamins — and security researchers reframed the comedy as indirect prompt injection: retrieved content steering the answer in Google’s own voice. This piece tracks the launch-week failures, the overview-bait SEO economy that followed, the manual-removal treadmill, provenance-aware retrieval as the real fix, and why RAG systems inherit the trust profile of their worst-cited source.

Continue ReadingGoogle AI Overviews: Prompt Injection Hits the Homepage of the Internet
Read more about the article Prompt Injection Is the New SQL Injection: The 20-Year-Old Mistake AI Is Repeating in 2026
Prompt injection is the new SQL injection — featured image

Prompt Injection Is the New SQL Injection: The 20-Year-Old Mistake AI Is Repeating in 2026

SQL injection stayed in the OWASP Top 10 for 20+ years. Prompt injection is the same bug with worse permissions — here’s the history, real examples, and the defense playbook.

Continue ReadingPrompt Injection Is the New SQL Injection: The 20-Year-Old Mistake AI Is Repeating in 2026
Read more about the article AST07 & AST08: Update Drift and Weak Scanning
OWASP Agentic Skills Top 10 series cover (cover_p7.png)

AST07 & AST08: Update Drift and Weak Scanning

The two post-deployment risks in the OWASP Agentic Skills Top 10: AST07 malicious updates riding channels with no signatures, pinning or freeze mode (40,000 exposed instances in 24 hours), and AST08 scanners that structurally lag base64, zero-width, pure-natural-language and .pyc evasion. Digest pinning, PASS/FAIL/INCOMPLETE pipelines, and Unicode strip ranges — dissected.

Continue ReadingAST07 & AST08: Update Drift and Weak Scanning
Read more about the article No Lockfile for Prose, No Sandbox for Code: AST05 and AST06, Explained
OWASP Agentic Skills Top 10 series cover (cover_p6.png)

No Lockfile for Prose, No Sandbox for Code: AST05 and AST06, Explained

Two halves of one failure mode in the OWASP Agentic Skills Top 10: AST05 external instructions that change after review (rug-pulls, reviewer bait-and-switch, transitive fetch chains) and AST06 skills that run on the host with full access. 135,000+ exposed instances, CVE-2026-32025, and the Air Security takeover POC.

Continue ReadingNo Lockfile for Prose, No Sandbox for Code: AST05 and AST06, Explained
Read more about the article AST03: Over-Privileged Skills and the DROP TABLE Problem
OWASP Agentic Skills Top 10 series cover (cover_p4.png)

AST03: Over-Privileged Skills and the DROP TABLE Problem

AST03 of the OWASP Agentic Skills Top 10: the risk where nothing is malicious and the damage still lands. Permission checks fire at tool-call level, not intent - so a SELECT-permitted skill can DROP TABLE. With Meta's inbox-deletion incident, LPCI and LAAF research, and the per-skill credential controls that close the gap.

Continue ReadingAST03: Over-Privileged Skills and the DROP TABLE Problem
Read more about the article Prompt Injection Attacks Explained: How Attackers Hijack AI Applications
Prompt injection attack chat and poisoned LLM brain

Prompt Injection Attacks Explained: How Attackers Hijack AI Applications

How attackers hijack AI applications with nothing but text: direct vs indirect injection, real incidents from Bing to EchoLeak, why no complete fix exists, and the layered architecture that actually contains it.

Continue ReadingPrompt Injection Attacks Explained: How Attackers Hijack AI Applications