Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
•
YouTube Security Videosheise & c't: Chatten ohne Mobilfunk?(29.09.2026 um 15:00 Uhr)
•
YouTube Security VideosGoogle Cloud Tech: Make your AI interview YOU first 💻(29.09.2026 um 15:00 Uhr)
•
YouTube Security VideosThis is why it’s time to give Firefox another look(29.09.2026 um 14:58 Uhr)
•
Windows Tipps & SecurityThe Copilot+ PC brand is dead: How to remap your Copilot key(29.09.2026 um 15:19 Uhr)
••••
Videos & Konferenzenheise & c't: Chatten ohne Mobilfunk?(29.09.2026 um 15:00 Uhr)
•••
YouTube Security Videosheise & c't: Chatten ohne Mobilfunk?(29.09.2026 um 15:00 Uhr)
•
YouTube Security VideosGoogle Cloud Tech: Make your AI interview YOU first 💻(29.09.2026 um 15:00 Uhr)
•
YouTube Security VideosThis is why it’s time to give Firefox another look(29.09.2026 um 14:58 Uhr)
•
Windows Tipps & SecurityThe Copilot+ PC brand is dead: How to remap your Copilot key(29.09.2026 um 15:19 Uhr)
••••
Videos & Konferenzenheise & c't: Chatten ohne Mobilfunk?(29.09.2026 um 15:00 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

Microsoft identifies seven new ways AI agents can be hacked

Microsoft has identified seven new failure modes in agentic AI systems, in addition to those it identified last year in its first Taxonomy of Failure Modes in Agentic AI Systems. Four things contributed to the growing list of ways…

0
↗ Quelle (csoonline.com)
Reagiere als Erste:r — dein Feedback zählt!








Microsoft has identified seven new failure modes in agentic AI systems, in addition to those it identified last year in its first Taxonomy of Failure Modes in Agentic AI Systems.





Four things contributed to the growing list of ways agentic AI can go wrong: the speed at which the technology went mainstream, the growing maturity of the Model Context Protocol (MCP) ecosystem, the rise of computer-use agents, and finally the gathering of more empirical evidence as researchers obtained more real-life findings.





The seven new failure modes it has identified are:






  • Agentic Supply Chain Compromise —agent behavior can be affected by natural language rather than malicious code;




  • Goal Hijacking — adversarial instructions appear aligned with legitimate task completion, while silently redirecting the agent’s terminal goal;




  • Inter-Agent Trust Escalation —a compromised agent asserts false identity or inflates claimed permissions to an orchestrator;




  • Computer Use Agent (CUA) Visual Attack — agents operating through graphical interfaces can be manipulated through content that carries adversarial instructions for the agent;




  • Session Context Contamination —an adversary introduces data that biases the agent’s reasoning in subsequent steps, without triggering safety controls at any individual step;




  • MCP / Plugin Abuse — an update on the original taxonomy’s coverage of function compromise around MCP and plugin protocols, specifically attack surfaces specific to those protocols;




  • Capability / Architecture Disclosure —an agent reveals internal implementation details such as tool names and schemas, system-prompt structure, memory interfaces, or consent/human-in-the-loop trigger logic.





Microsoft advises security teams using these definitions to influence their planning to inventory their your supply chain, generating a software bill of materials (SBOM) for every deployed agent, to verify agent identity cryptographically, not positionally, by issuing attestable credentials at provisioning, to add the seven new failure modes to their red-team coverage matrix, and to audit the human-in-the-loop user experience as a security control.





This article first appeared on InfoWorld.






2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph2 Knoten / 1 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Microsoft identifies seven new ways AI agents can be hacked

Thematisch verwandte Begriffe: Microsoft, identifies, seven, ways · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-96431 | Unrestricted Upload of File with Dangerous Type in the /WebAgenda/downlo…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag