AI Agents Are 'Gullible': Zero-Click Attacks Can Hijack Cursor, Copilot, ChatGPT, Salesforce Without User Interaction

Available in: 中文
2026-03-29T20:25:55.906Z·1 min read
At RSAC 2026, Zenity CTO Michael Bargury demonstrated that enterprise AI agents are vulnerable to zero-click prompt injection attacks that can hijack them to leak secrets, steal data, and manipulat...

At RSAC 2026, Zenity CTO Michael Bargury demonstrated that enterprise AI agents are vulnerable to zero-click prompt injection attacks that can hijack them to leak secrets, steal data, and manipulate users — all without any interaction.

The Core Problem

"AI is just gullible. We are trying to shift the mindset from prompt injection — because it is a very technical term — and convince people that this is actually just persuasion. I'm just persuading the AI agent that it should do something else."

What's Vulnerable

AI AgentAttack Scenario
CursorLeak developer secrets via poisoned Jira tickets
Salesforce AgentforceSend customer data to attacker server
ChatGPTSteal Google Drive data, manipulate user long-term
GeminiZero-click hijacking
Microsoft CopilotData exfiltration
Einstein (Salesforce)Unauthorized actions

How It Works

  1. Attacker finds automated AI agent integrations (e.g., Jira ticket creation from emails)
  2. Sends malicious prompt embedded in normal-looking content
  3. Agent automatically processes the poisoned input
  4. Agent performs attacker's desired action
  5. Zero user interaction required

The Cursor Example

Zenity wanted Cursor to leak secrets and send them to a controlled endpoint. Cursor has guardrails preventing this. So instead of asking it to steal secrets, they told it it was participating in a treasure hunt — and Cursor happily complied.

Long-Term Manipulation

"I can get ChatGPT to manipulate you. ChatGPT is a trusted advisor. It can be manipulated to answer whatever I want — and not just in the specific conversation, but long term."

Source: The Register (RSAC 2026)

↗ Original source · 2026-03-29T00:00:00.000Z
← Previous: RSAC Panel: Public-Private Partnerships Critical Against China's Typhoons — But Government Speakers All CancelledNext: US Army Receives First Self-Flying Black Hawk Helicopter from DARPA's ALIAS Program →
Comments0