Jul 1 – 5, 2026

2 verified items across one lane, from the week of Jun 29, 2026. Part of the Jul 1 – Sep 9, 2026 board.
Week of

Attacks2 itemsfull lane ↗

Zscaler ThreatLabz reports web content in the wild carrying indirect prompt injections aimed at autonomous browsing AI agents

Zscaler ThreatLabz documented live web infrastructure that plants instructions for AI browsing agents using SEO-poisoned keyword-stuffed HTML, text hidden off-screen via CSS such as left:-9999px, and weaponised JSON-LD structured data describing fake applications and payment offers. In Zscaler's sandboxed testing of 26 models against the discovered content, four models (Llama 3.3 70B, Llama 3.2 90B Vision, Gemini 3 Flash, Gemini 2.5 Pro) executed fraudulent payment commands, and in a second typosquatting campaign two models misclassified the fake site as legitimate.

Reported by researchersZscaler ThreatLabz ↗ ·

Sysdig documents JADEPUFFER, an LLM-driven agent that autonomously exploited Langflow and extorted a production database

Sysdig Threat Research reported an intrusion in which an LLM-driven agent exploited CVE-2025-3248, a missing-authentication flaw in Langflow's code validation endpoint, then harvested credentials from the Langflow host and MinIO storage, moved laterally to a production database server, compromised an Alibaba Nacos configuration service, and encrypted 1,342 configuration items using MySQL AES before dropping a ransom demand. Sysdig cited self-narrating payloads containing natural-language reasoning and a 31-second self-correction cycle after an initial exploitation step failed.

Reported by researchersSysdig ↗ ·

Sources cited this week

  1. Zscaler ThreatLabz reports web content in the wild carrying indirect prompt injections aimed at autonomous browsing AI agents — Zscaler ThreatLabz, Jul 2, 2026. zscaler.com ↗
  2. Sysdig documents JADEPUFFER, an LLM-driven agent that autonomously exploited Langflow and extorted a production database — Sysdig, Jul 1, 2026. sysdig.com ↗