New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
Summary
Researchers discovered a new attack called agent data injection (ADI), where attackers plant fake information in data that AI agents trust, like email sender names or button IDs, causing the agents to misclick or run unintended commands while still completing their original task. Unlike prompt injection (hiding commands in text input), ADI works by corrupting small facts the agent relies on, using fake punctuation characters that language models often misread as real delimiters even though a strict parser would ignore them. The attack successfully compromised real tools including web agents (Claude, Google's Antigravity, Nanobrowser) and coding assistants (Claude Code, OpenAI's Codex, Google's Gemini CLI).
Classification
Affected Vendors
Related Issues
Original source: https://thehackernews.com/2026/07/new-agent-data-injection-attack-can.html
First tracked: July 16, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%