The attack needs no exploit
Privileged access, untrusted content and an outbound call are enough. Every capable agent has all three.
AI Security
Legacy assurance was built for software that waits to be told what to do. These products are built for systems that act on their own — defending the tool boundary, attacking it first, and detecting when an agent's memory has been poisoned.
Privileged access, untrusted content and an outbound call are enough. Every capable agent has all three.
Intent detection on text is a losing game across languages and encodings. The action is the thing worth judging.
A poisoned memory keeps working long after the injected page is gone, and nothing in the transcript looks wrong.
The validation harness, the traces and the blocked exfiltration are all published.