Microsoft warns AI agents are being 'AutoJack'-ed to deliver RCE payloads by browsing untrusted websites

https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-2560-80.jpg
  • Microsoft’s Defender Security Research Team discloses “AutoJack,” a vulnerability chain in AutoGen Studio enabling RCE via malicious websites
  • Flaws included localhost channel misuse, skipped login checks, and arbitrary code execution, letting agents run attacker‑supplied programs
  • Issue existed only in early GitHub builds, fixed before release; highlights need for strict authentication and isolation of local control planes

Microsoft's Defender Security Research Team has disclosed a vulnerability chain in AutoGen Studio that lets a single malicious website achieve remote code execution (RCE) on a device running an AI agent.

AutoGen Studio is a program built by Microsoft Research for developing AI agents. The vulnerability chain was dubbed “AutoJack”, and it consists of three flaws which, when looked at separately, aren’t particularly troubling. Chained together, however, is a whole different story.

“The technique, which we call AutoJack, jacks the agent into becoming the attacker’s last-mile delivery vehicle by crossing the...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more