Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code

2026-06-12T13:24:11Z4b61c28630b80c89230992d031db8da31d0dae70ae9a9122f97ad115fae113d6
AI-agent-compromiseBitLocker-bypassCISA-KEVFortinetGreatXMLLangGraphLangflowMicrosoft-DefenderOpenClawOracle-PeopleSoftagentjackingbotnetlaw-enforcement-takedownnpm-install-scriptsphishing-as-a-serviceprotobuf.jsransomwareremote-code-executionsupply-chainzero-day

What happened

This digest aggregates multiple high-impact cybersecurity events: researchers disclosed a new "Agentjacking" technique that tricks AI coding agents (and similar attacks against OpenClaw) into executing attacker-controlled code or leaking secrets; LangGraph and Langflow vulnerabilities (including an exploited path-traversal RCE CVE-2026-5027) and other RCE chains were reported and patched; ShinyHunters exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) against universities; Fortinet/ Ivanti/ SAP updates address critical flaws including CVE-2026-25089; CISA added KEV entries such as CVE-2O

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
4b61c28630b80c89230992d031db8da31d0dae70ae9a9122f97ad115fae113d6
Enrichment time
2026-06-12T13:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.