AI agents are changing how users interact with software. Reportedly, these systems can browse websites, access files, call external tools and execute tasks on a user's behalf.
That expanded functionality is also creating a new cybersecurity attack surface. Researchers are finding ways in which malicious instructions and vulnerabilities in agent frameworks can turn AI systems into pathways for code execution, credential theft, and data exposure.
Prompt injection remains a major concern. Attackers can place hidden or malicious instructions inside webpages, documents or other external content that an AI agent processes.
OpenAI says, “Modern prompt-injection attacks increasingly resemble social engineering. Instead of simply trying to override an AI model, attackers attempt to manipulate the agent through information it encounters while completing a task.”
The company identified two vulnerabilities in Semantic Kernel that could allow attackers to influence tool parameters and execute code on the host. Microsoft said the affected vulnerabilities have been fixed and advised users to upgrade affected versions.
Microsoft also reported an attack chain involving AutoGen Studio in which untrusted web content could reach a local Model Context Protocol WebSocket and trigger processes on the host.
Cybercriminals are also experimenting with AI inside malware. Cisco Talos researchers identified CLOSEDQUORUM, a malware system that uses multiple large language models to help determine actions on compromised Windows machines.
Their research framework reportedly uncovered around 20 additional examples of AI-integrated malware, suggesting that AI-assisted malware is developing beyond isolated experiments.
Google Threat Intelligence has also observed threat actors moving from basic AI prompting toward agentic workflows and AI-enabled automation. In one Q2 2026 case, attackers reportedly compromised a cloud resource and built an agent-enabled credential-harvesting campaign in under six hours.
Also Read: Anthropic Unveils Claude Opus 5.5 with Faster, Cheaper AI Performance