Sunday, October 4, 2026

This popular AI agent could be hacked by a single email — with potentially disastrous consequences


  • Researchers bypassed Manus prompt-injection protections, achieving code execution through JSFuck obfuscation
  • Hidden email prompts were decoded and executed before Manus flagged suspicious activity
  • Flaw was patched, highlighting risks from AI agents with broad third-party access

If you think email-borne prompt injection attacks against Manus were a thing of the past – think again.

Security researchers from Salt Labs have found a way around the guardrails, and while this particular technique was subsequently fixed, chances are there are others out there, just as effective.

“Honey, I deployed malware”

Related Articles

Latest Articles