Researchers disclosed Workflow Identity Hijacking, an authorization-design weakness in enterprise AI automations that lets an unauthenticated party submit a benign request through channels such as public inboxes, web forms, issue trackers, support platforms, shared documents, or chat. The workflow can then invoke connected tools using a privileged non-human identity, service account, developer API key, or creator credential, potentially retrieving and returning internal data to the attacker.
The exposure does not require prompt injection, model jailbreaking, credential theft, or model manipulation: the AI and its tools perform their intended functions, but the original requester's identity and permissions are not carried into downstream actions. Defenders should inventory AI workflows and associated privileges, trace untrusted inputs, bind sensitive operations to authenticated requester authorization, replace persistent administrative credentials with short-lived scoped tokens, separate sensitive-data retrieval from external responses, treat model output as untrusted, and log requester-to-action authorization context.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Noma Security researchers identified Workflow Identity Hijacking, an authorization-design weakness in which an untrusted requester can trigger an AI workflow that acts with a privileged non-human identity without validating the requester’s entitlements. The issue can enable unauthorized access or disclosure of internal data without prompt injection, model jailbreaking, or credential theft.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcesecuritymagazine.com
Open sourcenoma.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.