AI · 67 days ago
Autonomous web-browsing agents now have a trust problem, not just a phishing problem. If the page can feed the agent instructions it will obey, then the content itself becomes the attack surface, and the wrong response is to assume a human will catch the fake site before anything happens.
Zscaler found two active campaigns that used SEO poisoning, typosquatting, and hidden prompt injection in site markup to steer agents into crypto payments or to treat a fake DeBank site as legitimate. In tests across 26 LLMs, four were manipulated into making a payment, and two miscategorized the fraudulent site as trusted DeBank; the affected pattern is any assistant that can browse and take actions on a user’s behalf.
The risk persists wherever these agents can authorize payments or account actions. Patching the browser or training the user does not fix a control point that sits in the page content the agent is willing to obey.
5 sources covering this story
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
AI Now’s Friendly Fire PoC shows Claude Code and Codex running README-planted payloads on hosts when autonomous command approval is enabled.
CrowdStrike Uncovers New Prompt Injection Techniques
CrowdStrike expands its prompt injection taxonomy to 200+ techniques, revealing new AI attack methods to help security teams defend AI agents and LLMs.
Zscaler finds autonomous agents succumb to IPI traps
Hidden instructions on websites con agents into falling for scams that a human would see through.
Indirect Prompt Injection in Web Content Targets AI Agents
Zscaler found sites hiding prompt-injection text to manipulate AI agents into crypto payments
Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments
Researchers uncovered two campaigns embedding indirect prompt injections in malicious websites to exploit autonomous AI agents browsing the web.
Part of the PlainSec briefing for 2026-07-09