Home Cyber Security

ZombieAgent Exposes a Growing Blind Spot in Agentic AI Security

Radware’s discovery of ZombieAgent highlights a critical and growing risk facing organisations adopting agentic AI platforms: a lack of visibility into how AI agents interpret untrusted content and execute actions autonomously in the cloud.

ZombieAgent is a zero-click vulnerability that allows attackers to hijack AI agents without requiring any user action. By embedding hidden instructions into everyday content such as emails or documents, attackers can manipulate agents into leaking sensitive data and performing unauthorised actions without triggering traditional security tools.

Unlike conventional cyberattacks that rely on endpoint compromise or network intrusion, ZombieAgent operates entirely within the AI service layer. This means no firewall alerts, no endpoint detection warnings, and no suspicious traffic flowing through corporate infrastructure.

Radware says the vulnerability demonstrates a fundamental structural weakness in today’s agentic AI platforms, where agents are trusted to access sensitive systems, summarise communications, initiate workflows and make decisions often without sufficient safeguards around how they process external content.

“Enterprises trust these agents with high-value data and decision-making authority, yet they have little insight into what instructions agents are following or what actions they’re executing in the cloud,” said Pascal Geenens, Vice President of Threat Intelligence at Radware. “That creates a dangerous blind spot.”

ZombieAgent also introduces the risk of persistent agent compromise. By embedding malicious rules into an agent’s memory, attackers can ensure the AI continues to exfiltrate data every time it is used long after the original malicious content has been processed.

For business leaders, the implications are clear: AI security can no longer be treated as an extension of endpoint or network security. As agentic AI adoption accelerates, organisations must rethink governance, monitoring and threat modelling for AI systems that operate beyond traditional security boundaries.