A newly disclosed class of attack against AI agents can make forged data appear trusted, tricking coding assistants and browser agents into wrong clicks or the execution of an attacker's commands—even when the user is prompted to approve the action. In a paper posted to arXiv on July 6, 2026, researchers from Seoul National University and collaborators define and demonstrate what they call Agent Data Injection (ADI), a variant of indirect prompt injection that they argue slips past today's leading defenses.
Continue reading
The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in✓ Signed in — this article isn’t included in your current plan.