BREAKING
'Rogue Agent' Flaw in Dialogflow CX
How the Attack Spread
1
Edit Code Blocks
↓
2
Inject Python
↓
3
Abuse shared Cloud Run
↓
4
Lateral move to bots
What Attackers Could Do
Data Exposure
●
Read conversation history
●
Capture user input
●
IMDS token retrieval
Tampering
●
Override respond() output
●
Phishing lures
●
Evade Cloud Logging
0
%
Fortune 500 use AI agents
0
x
permission needed
Reported Nov 2025, Fixed Jun 2026
Audit Playbook Logs, Review Code Blocks
AI NEWS BLITZ
Varonis found a flaw that let one Dialogflow CX bot hijack others, and Google has now patched it.