securityaffairs.com 21 Sept 2026, 08:27 UTC

AI Agents Expose New Attack Paths Through Skills and Memory

AI Agents Expose New Attack Paths Through Skills and Memory
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Available

RESEARCH published during February 2026 indicates that AI agents, rather than standalone models, are becoming a broader cybersecurity target because they combine persistent memory with skills, external tools, protocols and the ability to act on connected systems. The research mapped by Security Affairs to MITRE ATLAS describes an attack lifecycle covering AI-assisted reconnaissance, poisoned tools, prompt injection, jailbreaks, data theft and system impact.

One study involving Nicholas Carlini and Florian Tramèr demonstrated large-scale deanonymisation using an LLM agent to extract identity signals, find possible matches and verify them.

The agent supply chain was a particular focus. An empirical analysis of almost 98,380 skills from two marketplaces identified 157 confirmed malicious skills, classified mainly as data stealers or agent hijackers. Researchers reported that malicious behaviour could be concealed in documentation, while other work found that agents performed harmful actions after compromised skills were installed. Studies also examined automated prompt injection and attacks against the Model Context Protocol.

The article cites EchoLeak (CVE-2025-32711), which enabled zero-click data exfiltration from a Copilot assistant through prompt injection, and CurXecute (CVE-2025-54135/54136), which enabled remote code execution through an IDE’s MCP implementation.

In an 11-case red-team exercise, autonomous agents with memory, email, Discord, filesystem and shell access disclosed sensitive information, performed destructive actions, spoofed identities and propagated unsafe behaviour between agents. The recommended response is to inventory agents, skills and MCP servers; verify, sandbox and pin tool versions; and monitor runtime behaviour, including context and tool calls, rather than relying only on message or network monitoring.

View full article

Article by CyberSIXT