Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
2026-06-12T13:24:11Z•4b61c28630b80c89230992d031db8da31d0dae70ae9a9122f97ad115fae113d6
AI-agent-compromiseBitLocker-bypassCISA-KEVFortinetGreatXMLLangGraphLangflowMicrosoft-DefenderOpenClawOracle-PeopleSoftagentjackingbotnetlaw-enforcement-takedownnpm-install-scriptsphishing-as-a-serviceprotobuf.jsransomwareremote-code-executionsupply-chainzero-day
What happened
This digest aggregates multiple high-impact cybersecurity events: researchers disclosed a new "Agentjacking" technique that tricks AI coding agents (and similar attacks against OpenClaw) into executing attacker-controlled code or leaking secrets; LangGraph and Langflow vulnerabilities (including an exploited path-traversal RCE CVE-2026-5027) and other RCE chains were reported and patched; ShinyHunters exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) against universities; Fortinet/ Ivanti/ SAP updates address critical flaws including CVE-2026-25089; CISA added KEV entries such as CVE-2O
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 4b61c28630b80c89230992d031db8da31d0dae70ae9a9122f97ad115fae113d6
- Enrichment time
- 2026-06-12T13:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.