HeadlinesBriefing favicon HeadlinesBriefing.com

DEF CON 34 AI एजेंट सुरक्षा

Hacker News •
×

As AI agents automate more tasks, they become more capable—and more vulnerable. At Bug Bounty Village during DEF CON 34, Inti De Ceukelaire, Founding Member of Intigriti, demonstrated how attackers can abuse AI customer service agents through prompt injection and email spoofing, earning over $50,000+ in bounties in just a few weekends. His research revealed that agents with transcript or email-sending features can be tricked into sending phishing emails by manipulating the From header, making malicious messages appear to come from trusted sources like [email protected].

In one case, a chatbot allowing both transcript receipt and email interaction had flawed validation, enabling spoofed emails to trigger unauthorized actions. Attackers further exploited CC headers to receive confidential responses, such as billing statements or profile data, even when the victim remained unaware. Even when email authentication blocked spoofing, researchers found abuse possible via RFC 822’s allowance of multiple From headers.

These techniques require no traditional scanners like Burp Suite—only clever prompt engineering and protocol manipulation. The findings highlight critical gaps in how AI agents validate identity and authorize actions, urging developers to implement strict sender verification and least-privilege tool access. Special thanks to Inti De Ceukelaire for his research and talk at BBV during DEF CON 34.

Full slides: go.intigriti.com/HHITLS2026.