Cornell Tech researchers disclosed Web Agent Retrieval Poisoning (WARP), a technique that lets attackers manipulate AI deep-research systems by planting short pieces of user-generated content on sources those tools frequently retrieve, especially Reddit, Wikipedia, and forums. The study found that a Reddit comment of roughly 13 words could be enough to influence synthesized reports, causing systems to introduce fabricated entities, fake brands, fraudulent services, or other misinformation. The attack requires only public search visibility and a Reddit account, making it accessible to low-resource attackers and disinformation operators.
In testing across 176 queries and 11 topic clusters, researchers found open-source agents such as STORM and Co-STORM were highly susceptible, while reconnaissance suggested commercial exposure in Google Gemini Deep Research and, to a lesser extent, OpenAI Deep Research. Using the safe GeoStorm framework rather than live sites, the team showed poisoned content could steer outputs in 38% to 51% of cases, rising to 62% when the same message appeared across multiple sources, including examples where AI recommended fictional restaurants and dating apps. The paper said common defenses such as blocking user-generated content, input and output filtering, and perplexity-based detection were either ineffective or degraded report quality, pointing to a broader structural weakness in deep-research agents that rely on open-web content.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
An academic paper from Cornell Tech disclosed Web Agent Retrieval Poisoning (WARP), a technique for manipulating deep-research AI systems by poisoning frequently retrieved user-generated content such as Reddit threads and Wikipedia pages. The paper also released code and a simulation framework to support defensive research.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.