BREAKING
'Rogue Agent' Flaw in Dialogflow CX
How the Attack Spread
1Edit Code Blocks
2Inject Python
3Abuse shared Cloud Run
4Lateral move to bots
What Attackers Could Do
Data Exposure
Read conversation history
Capture user input
IMDS token retrieval
Tampering
Override respond() output
Phishing lures
Evade Cloud Logging
0%
Fortune 500 use AI agents
0x
permission needed
Reported Nov 2025, Fixed Jun 2026
Audit Playbook Logs, Review Code Blocks
AI NEWS BLITZ
Varonis found a flaw that let one Dialogflow CX bot hijack others, and Google has now patched it.