Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-platform-securityai-enabled-threat-activitysearch-ad-manipulationdata-exfiltration-method

Indirect Prompt Injection and AI Agent Abuse Expands Real-World Attack Surface

Updated 3mo agoFirst seen Mar 3, 202610 sources

Security researchers and industry reporting describe prompt injection—especially web-based indirect prompt injection (IDPI)—as an increasingly practical technique for compromising or manipulating LLM-powered agents embedded in browsers and automated content pipelines. Palo Alto Networks Unit 42 reported in-the-wild IDPI activity where malicious instructions are hidden in web content that an agent later ingests, with observed objectives including AI-based ad review evasion and SEO manipulation that promotes phishing infrastructure. Separately, Zenity Labs detailed a now-patched issue in Perplexity’s Comet AI browser where attackers could embed instructions in a calendar invite to coerce the agent into accessing file:// resources and potentially pivoting into sensitive data such as an unlocked 1Password extension vault, illustrating how agentic tooling can bypass traditional browser-origin assumptions.

Threat reporting also shows adversaries operationalizing AI to scale exploitation. Team Cymru linked an AI-assisted Fortinet FortiGate targeting campaign (previously reported by Amazon Threat Intelligence as compromising 600+ devices across 55 countries using services like Claude and DeepSeek) to use of CyberStrikeAI, an open-source Go-based platform that integrates 100+ security tools and was observed from multiple IPs (primarily hosted in China/Singapore/Hong Kong, with additional infrastructure elsewhere). Multiple commentaries and briefings emphasize that conventional “filter the prompt” defenses are insufficient because LLMs lack a native separation between instructions and data; they call for defense-in-depth around AI pipelines, including least-privilege agent permissions, auditable tool use, and stronger identity/workload controls as agent deployments multiply. Several items in the set are unrelated (geopolitical cyber activity, workforce/culture pieces, jobs, and product/market commentary) and do not materially inform the prompt-injection/agent-abuse story.

Share:
Indirect Prompt Injection and AI Agent Abuse Expands Real-World Attack Surface
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

15 events from the most recent confirmed update back to the earliest known activity.

15 EVENTS
Mar 3, 20264mo ago

Team Cymru links CyberStrikeAI to global AI-driven FortiGate attacks

On March 3, 2026, Team Cymru reported that an AI-assisted campaign targeting Fortinet FortiGate appliances used the open-source CyberStrikeAI offensive platform. The activity was associated with automated mass scanning from 212.11.64[.]250 and attributed in reporting to a suspected Russian-speaking threat actor, while the tool's developer showed possible ties to Chinese state-linked entities.

Zenity publicly discloses Comet browser calendar invite exploit chain

On March 3, 2026, reporting detailed Zenity Labs' findings that Perplexity's Comet AI browser could be exploited through calendar invitations to access local files and potentially abuse an unlocked 1Password session. The disclosure also noted Perplexity's prior fixes and framed calendar entries as an underappreciated attack surface for AI agents.

Unit 42 reports indirect prompt injection is now observed in the wild

On March 3, 2026, Palo Alto Networks Unit 42 published research stating that web-based indirect prompt injection had moved from proof-of-concept to active real-world weaponization. The report documented additional detections involving SEO poisoning, unauthorized payment attempts, data exfiltration, and destructive commands, and recommended defense-in-depth mitigations.

AIUC-1 Consortium issues 2025 briefing on enterprise AI agent risks

A 2025 briefing cited on March 3, 2026 by the AIUC-1 Consortium, with input from Stanford's Trustworthy AI Research Lab and more than 40 security executives, identified autonomous overprivileged agents, shadow AI visibility gaps, and prompt injection trust failures as the dominant enterprise AI risk areas. It recommended technical controls such as tool-call validation, prompt-injection logging, containment testing, and continuous adversarial testing.

Mar 2, 20264mo ago

Samsung SDS publishes top enterprise cyber threats for 2026

On March 2, 2026, Samsung SDS published an assessment naming AI-based threats, ransomware, cloud security issues, phishing/account takeovers, and data security as the five most significant enterprise cybersecurity risks for 2026. The report recommended mitigations including least privilege for AI agents, hardened backups, CNAPP adoption, MFA, and stronger data access controls.

Feb 26, 20264mo ago

Amazon discloses AI-assisted compromise of 600+ FortiGate devices

Before March 2026, Amazon Threat Intelligence disclosed that an attacker used generative AI services including Anthropic Claude and DeepSeek to compromise more than 600 FortiGate devices across 55 countries. This disclosure established the scale of the FortiGate campaign later tied to CyberStrikeAI activity.

Feb 1, 20265mo ago

Perplexity issues second patch that closes Comet exploit vector

In February 2026, Perplexity released a subsequent patch that reportedly closed the specific Comet browser exploit path involving file:// access and calendar-invite-delivered indirect prompt injection.

Jan 25, 20265mo ago

1Password publishes advisory and adds hardening options

In late January 2026, 1Password issued an advisory related to the Comet browser research and introduced hardening options. The company noted the risk stemmed from an AI agent operating inside an already authenticated session rather than a flaw in 1Password's external security model.

Jan 20, 20265mo ago

CyberStrikeAI infrastructure observed in FortiGate attack activity

Between January 20 and February 26, 2026, Team Cymru observed 21 unique IP addresses running the open-source CyberStrikeAI platform, with infrastructure concentrated in China, Singapore, and Hong Kong. The tooling was linked to AI-assisted activity targeting Fortinet FortiGate devices.

Jan 1, 20266mo ago

Perplexity ships initial Comet fix for calendar invite attack path

In January 2026, Perplexity released an initial fix for the Comet browser issue involving indirect prompt injection via calendar invites. Zenity later found a way to bypass this first remediation.

Dec 1, 20257mo ago

Unit 42 detects indirect prompt injection against ad review system

In December 2025, Palo Alto Networks Unit 42 observed a real-world web-based indirect prompt injection attempt targeting an AI-driven advertisement review system. The attack used concealed prompt-delivery techniques on a scam advertorial page to try to bypass the review process.

NCSC warns prompt injection may be unsolved at the input level

In December 2025, the UK National Cyber Security Centre warned that prompt injection in LLMs may be an unsolved or even unsolvable problem at the input layer because models do not inherently separate instructions from data.

Nov 1, 20258mo ago

BlackBoxAI extension research uncovers prompt leakage and code execution risks

In November 2025, ERNW researcher Ahmad Abolhadid analyzed the BlackBoxAI Visual Studio Code extension and showed it could be manipulated to reveal system prompts and execute attacker-supplied code through indirect prompt injection. The demonstrations included reverse-shell compromise and repeated attempts to coerce privileged execution.

Oct 1, 20259mo ago

Perplexity notified of Comet calendar invite prompt-injection flaw

In October 2025, Zenity Labs reported to Perplexity that its Comet AI browser could be manipulated through indirect prompt injection delivered via calendar invitations, enabling access to local files and other sensitive resources under certain conditions.

Jan 1, 20233y ago

OWASP ranks prompt injection as top LLM application risk

OWASP has listed prompt injection as the top vulnerability in its LLM Applications Top 10 since 2023, establishing it as a leading security concern for AI-enabled systems.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

59 LINKEDOpen in app
Affected products
9 linked
1passwordPrisma BrowserAmazon Web ServicesAzureVisual Studio CodeChatgptChatgptGoogle MeetDeepseek
Organizations
48 linked
LexisNexisPrivacy-PCAmazon Web Services1passwordGoogleSamsungsdsUipathCisco SystemsDatabricksElasticZscalerTeam CymruPricewaterhouseCoopersErnst & YoungPalo Alto NetworksDeepseekSAPDomainToolsDeutsche BörseZenityAnthropicRecorded FutureConfluentDark ReadingFortinetCyber Threat AllianceOpenaiGartnerScale AIPerplexityStripePayPalLayerXMicrosoft CorporationGitHubBitsightForbesSonicwallThe Cyber ExpressKnownsec 404ERNWAlamyZoonar GmbHVirtue AISimeioAllianceBernsteinAIUC-1 ConsortiumBlackBoxAI
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.