International Cyber Expo International Cyber Expo
  • About Us
Friday, 2 October, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Malicious Email Could Hijack AI Agent and Access Connected Accounts

Security researchers have uncovered a now-fixed vulnerability in agentic AI platform Manus that could have allowed attackers to hijack an AI agent through a single malicious email

by Guru Writer
October 2, 2026
in Editor's News, Features
Malicious Email Could Hijack AI Agent and Access Connected Accounts
Share on FacebookShare on Twitter

Security researchers have uncovered a now-fixed vulnerability in agentic AI platform Manus that could have allowed attackers to hijack an AI agent through a single malicious email and potentially access a user’s connected accounts.

Researchers at Salt Labs, the research arm of Salt Security, found that Manus could interpret malicious instructions embedded within an incoming email and execute them when asked by a user to check their messages.

Manus is a general-purpose agentic AI platform capable of independently carrying out multi-step tasks including research, data analysis, content creation and software development. The platform can also connect to third-party services such as email, cloud storage and code repositories.

According to Salt Labs, this connectivity created an opportunity for an indirect prompt injection attack, in which malicious instructions contained within external content are interpreted by an AI system as commands.

During testing, researchers initially sent an email containing a direct malicious command. Manus detected and flagged the instruction, suggesting its existing guardrails were capable of recognising the attack.

However, researchers were subsequently able to disguise the command using an obscure JavaScript obfuscation technique. Manus decoded and executed the hidden code and, while the platform produced a security warning, Salt Labs said the warning appeared only after the code had already executed.

The researchers were then able to establish a reverse shell within the environment and locate credentials and tokens associated with third-party services connected to the test account.

According to Salt Labs, a successful real-world exploitation of the vulnerability could therefore have potentially enabled an attacker to reach services including a victim’s email, cloud storage and code repositories.

Significantly, the attack chain did not require the victim to click a malicious link, download a file or hand over their password. Researchers said it required just two events: a malicious email arriving in the victim’s inbox and the user subsequently asking Manus to check their messages.

The vulnerability was responsibly disclosed and has since been resolved, meaning the attack described by Salt Labs is no longer exploitable.

However, the researchers argue the findings demonstrate a wider security challenge facing agentic AI systems: detecting malicious activity may not be enough if an autonomous agent has already performed the action before a human can intervene.

As organisations increasingly give AI agents access to business applications, APIs and sensitive data, Salt Labs said security controls will need to extend beyond inspecting prompts and model behaviour to governing what agents are permitted to do across connected systems.

“The agentic domain is relatively new, and the industry is still learning how to use it correctly, and so are attackers,” said Yaniv Balmas, Head of Research at Salt Security.

“Guardrails are an important part of any agentic system that handles untrusted input, but they are often simply not enough. Anyone designing an agentic system should build robust, layered defenses rather than trusting guardrails to provide all the protection, exactly as we learned to do with traditional services.”

Balmas added that as adoption of agentic AI grows, he expects attacks targeting these systems to become an increasingly common threat vector.

ShareTweet
Previous Post

RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant

Next Post

Cybersecurity Awareness Month: AI agents are users too, and they need governing like it

Recent News

Cybersecurity Awareness Month: AI agents are users too, and they need governing like it

Cybersecurity Awareness Month: AI agents are users too, and they need governing like it

October 2, 2026
Malicious Email Could Hijack AI Agent and Access Connected Accounts

Malicious Email Could Hijack AI Agent and Access Connected Accounts

October 2, 2026
RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant

RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant

October 1, 2026
Huntress and ALSO partner to put managed security in reach of more European MSPs

Huntress and ALSO partner to put managed security in reach of more European MSPs

October 1, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol