How to Hack an AI Agent via a Regular Email
AI agents are gaining more privileges: they can read databases, call external APIs, and execute code. This is convenient until an attacker feeds the agent malicious text.
Attacks target not the code, but the context. The instruction is hidden in an email, document, or comment, and the language model executes it as its own command.
There are confirmed cases of such vulnerabilities:
- EchoLeak: a vulnerability in Microsoft 365 Copilot allowed access to data via an incoming email without needing to open it
- CamoLeak: a hidden comment in a pull request forced GitHub Copilot to extract code from private repositories
- SearchLeak: another scenario for information leakage through context manipulation
The root of the problem lies in the fact that large language models (LLMs) cannot be considered a trusted component. They do not distinguish between data and commands, and the logic of their decisions remains a black box.
Therefore, protection should focus not on the model itself, but on everything surrounding it. Kaspersky Lab has released the guide "AI Agent Security Through the Lens of Cyber Immunity," containing diagrams and facts.
The material presents analyses of real attacks via context, explanations for why LLMs cannot be trusted, and methods for isolating the agent with control over its tools.







