AI agents are moving from sandbox demos into real business workflows—and that changes security fast. Instead of focusing only on the model or a single prompt weakness, the “attack surface” now includes the entire agent action chain: how it plans, calls tools, interacts with systems, and completes multi-step tasks. Microsoft summarized the last 12 months of red-team learnings on deployed agent systems and updated its taxonomy in “Agentic AI System Failure Modes” to v2.0. The update adds 7 new failure patterns—and the big warning is clear: evaluate agents like controllable runtime entities, not like static chatbots. They also highlight at least four emerging risks to test, especially when agents run on production data or call external APIs: 1) Target hijacking (attacker steers the agent’s final goal while keeping it “legit”). 2) Visual attacks against computer-use agents (tiny or hidden UI cues, image-based prompt injection). 3) Context poisoning across work stages (early-step data silently corrupts later reasoning). 4) Capability/architecture disclosure (leaking tool names, prompt structure, memory interfaces, or HitL paths). Mitigation idea: build an SBOM for agents—track tools, MCP servers, prompt templates, dependencies, and version changes with the same rigor as software supply chains. #AIAgents #AppSec #RedTeam #SecurityEngineering #SBOM #ThreatModeling
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论