Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code

2026-06-12T19:24:09Z9397a5dd8b7e8204e21bcd9f97e416c1bfeac7c5c2dc4b298afb96a77c57cfee
agentjackingai-agent-attacksbitlocker-bypasslangflowlanggraphlaw-enforcement-takedownsmicrosoft-defendernpm-install-scriptsopenclawpeopleSoftprotobuf.jsransomwareremote-code-executionsupply-chainzero-day

What happened

The collection highlights a surge in high-impact security events: new AI-agent attack classes (Tenet Security's "Agentjacking" via crafted Sentry error reports, OpenClaw exploits, and other inputs that coerce self‑hosted agents into running attacker code or leaking secrets); multiple high-severity/active-exploitation vulnerabilities in AI frameworks and enterprise products (LangGraph critical RCE chain, Langflow path-traversal CVE-2026-5027 under active exploitation, and Oracle PeopleSoft CVE-2026-35273 exploited by ShinyHunters); large-scale vendor patching (Microsoft fixing 206 flaws, Forti/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
9397a5dd8b7e8204e21bcd9f97e416c1bfeac7c5c2dc4b298afb96a77c57cfee
Enrichment time
2026-06-12T19:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.