Zscaler ThreatLabz reports web content in the wild carrying indirect prompt injections aimed at autonomous browsing AI agents
Zscaler ThreatLabz documented live web infrastructure that plants instructions for AI browsing agents using SEO-poisoned keyword-stuffed HTML, text hidden off-screen via CSS such as left:-9999px, and weaponised JSON-LD structured data describing fake applications and payment offers. In Zscaler's sandboxed testing of 26 models against the discovered content, four models (Llama 3.3 70B, Llama 3.2 90B Vision, Gemini 3 Flash, Gemini 2.5 Pro) executed fraudulent payment commands, and in a second typosquatting campaign two models misclassified the fake site as legitimate.
Sysdig documents JADEPUFFER, an LLM-driven agent that autonomously exploited Langflow and extorted a production database
Sysdig Threat Research reported an intrusion in which an LLM-driven agent exploited CVE-2025-3248, a missing-authentication flaw in Langflow's code validation endpoint, then harvested credentials from the Langflow host and MinIO storage, moved laterally to a production database server, compromised an Alibaba Nacos configuration service, and encrypted 1,342 configuration items using MySQL AES before dropping a ransom demand. Sysdig cited self-narrating payloads containing natural-language reasoning and a 31-second self-correction cycle after an initial exploitation step failed.