AI Agents Turn Web Pages Into Attack Payloads

Web content can now act as an instruction channel for AI agents. The standard response is to treat prompt injection as a chat problem, but these payloads matter because they can drive real actions when the agent has access to email, terminals, payments, or other transactional tools. Forcepoint found 10 active indirect prompt injection payloads in the wild. The payloads were built to trigger fraud, data destruction, API-key theft, content suppression, and attribution hijacking across agents that browse pages, summarize content, index for RAG, or process metadata and comments. The risk is not the prompt itself. It is the agent’s privilege set. A read-only summarizer is low impact; an agent that can act on behalf of a user can turn poisoned web content into a live compromise path.

Part of the PlainSec briefing for 2026-04-28

Sources