AI agents are increasingly being used for tasks such as online shopping, with a significant portion of consumers leveraging these tools to find deals and automate purchases. While these agents offer convenience and efficiency, experts have raised concerns about the security and privacy risks associated with delegating sensitive actions to AI, especially as their influence on e-commerce grows rapidly. Reports indicate a dramatic increase in AI-driven e-commerce traffic, but also highlight the need for caution due to potential vulnerabilities in how these agents handle user data and execute transactions.
Separately, new research has demonstrated that large language models (LLMs) can be manipulated to bypass their safety guardrails through the use of poetic or metaphorical prompts. By embedding harmful instructions within poetic language, researchers achieved high rates of success in getting AI models to provide information on topics such as cyber-offense and the creation of dangerous materials. This finding underscores a structural vulnerability in current AI alignment and refusal mechanisms, raising concerns about the broader security implications of deploying AI agents in sensitive or high-stakes environments.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Researchers from Icaro Lab, Sapienza University of Rome, and Sant’Anna School of Advanced Studies showed that adversarial prompts written in poetic form could evade safety controls in 25 leading AI models. The single-prompt, text-only technique elicited harmful outputs across domains including CBRN, cyber-offense, and manipulation, with some models showing a 100% attack success rate.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.