This popular AI agent could be hacked by a single email — with potentially disastrous consequences
- Researchers bypassed Manus prompt-injection protections, achieving code execution through JSFuck obfuscation
- Hidden email prompts were decoded and executed before Manus flagged suspicious activity
- Flaw was patched, highlighting risks from AI agents with broad third-party access
If you think email-borne prompt injection attacks against Manus were a thing of the past - think again.
Security researchers from Salt Labs have found a way around the guardrails, and while this particular technique was subsequently fixed, chances are there are others out there, just as effective.
“Honey, I deployed malware”
Prompt injection attacks are nothing new. They have been around since the earliest days of AI agents, and the premise is very simple. AI cannot distinguish between prompts and data to be analyzed. If a user prompts an AI agent to summarize an email they received, and that email contained a separate prompt, the AI would execute both.
And if that “layer two”...
Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE