AI assistants and agents are increasingly integrated into both personal and enterprise workflows, raising significant concerns about data privacy and security. Recent research highlights that users often grant AI agents more data access than necessary, sometimes sharing sensitive information out of convenience or misunderstanding, while still withholding highly sensitive data like Social Security numbers in many cases. This over-permissioning and under-permissioning dynamic underscores the challenge of designing AI systems that request and handle data appropriately, balancing user convenience with privacy protection.
At the same time, AI assistants have become attractive targets for cyber attackers, who exploit their growing presence in organizations to launch new types of attacks such as prompt injection. These attacks manipulate AI agents through crafted text-based payloads, bypassing traditional email and endpoint security measures. As AI agents expand the enterprise attack surface, security teams face new challenges in defending against threats that target machine reasoning rather than human behavior, emphasizing the urgent need for updated security architectures and user awareness around AI-driven workflows.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
A reported attack dubbed Gemini Jack showed how hidden instructions embedded in documents or emails could manipulate Google's Gemini assistant into leaking sensitive information. The attack was triggered by routine employee queries, exploiting the AI's legitimate access rather than stolen credentials.
Reporting described a rise in attacks targeting AI assistants and agents, with adversaries using prompt injection and related AI-specific techniques to manipulate automated actions. The coverage noted that traditional email and phishing defenses often fail against these attacks because agents may process hidden instructions in metadata or HTML automatically.
The study also introduced a hybrid AI model that predicted user permission preferences with high accuracy. Experts cautioned that prediction accuracy alone is not sufficient for secure deployment, especially in regulated environments.
The same research highlighted security concerns around AI permission models, including prompt injection attacks and risks from running permission inference on shared infrastructure. Researchers advised organizations to isolate these systems and ensure compliance rules take precedence over learned user preferences.
A research study examined how people respond when AI agents request access to personal data for different tasks. It found users often allow automatic sharing for convenience but become more restrictive with sensitive data or after agent mistakes, creating both over-permissioning and under-permissioning risks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
securitysenses.com
Open sourcehelpnetsecurity.com
Open sourcetechrepublic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.