SEPTEMBER 8, 2026 16:40While organizations continue to worry about employees accidentally entering trade secrets into ChatGPT, Copilot, Claude, or Gemini, the real threat has moved to an entirely different arena: the AI supply chain. A new study from early 2026 reveals a troubling reality: 36% of the AI add-ons that organizations install today contain vulnerabilities or hidden malicious prompts.Imagine a scenario in which your organization’s AI agent reads an innocent meeting invitation or scans a routine document and, without you even having to click a link, executes malicious code that extracts sensitive information. The Zero-Click era has reached the world of AI, and most organizations are trying to fight it with yesterday’s weapons.Today’s AI agents are equipped with permissions and execution capabilities that did not exist in the previous generation of tools, known as stateless LLMs. Once such an agent gains access to email, documents, calendars, and even code repositories, it operates almost like a regular employee and may become, without your knowledge, a tool in the attacker’s hands.While the security approach of many organizations has been left behind, complex threats are being addressed through strategies designed to prevent prompts containing sensitive information from being entered or unwanted output from being generated by chatbots. These strategies were not designed to deal with the remote exploitation or manipulation of AI.The future of AI software development may not be about who can generate the most code, but who can decide which code is worth trusting. (credit: SHUTTERSTOCK)Cyberwarfare in the age of agents is a multi-front warThe transition to autonomous agents has opened five new attack vectors in the supply chain through which attackers attempt to penetrate organizational systems.These are connectors (permissions that provide direct access to employees’ email accounts, Google Drive, Jira, or GitHub); skill files (expanding an agent’s capabilities, such as data analysis, and program it to perform automated actions, which attackers exploit); plugins (add-ons that expand the agent’s permissions and can embed malicious persistent commands that run every time the agent is activated); MCP servers (connecting the agent to additional systems within the organization to which it previously had no access); and add-on marketplaces (platforms from which extensions can be installed at the click of a button, without a secure code-signing mechanism).Each of these vectors enhances the AI agent’s capabilities but at the same time expands the attack surface. Instead of trying to breach the network directly, attackers exploit the supply chain. They embed hidden white text in seemingly innocent Word documents or inject malicious code into calendar meeting descriptions. The risk materializes during legitimate, everyday use of the agent and stems from the drive for greater efficiency that characterizes the AI revolution.Employees ask an AI agent to summarize a Word document or review their weekly meetings without suspecting that the content passed to it could serve as an attack vector. In practice, however, the innocent agent reads the hidden commands, interprets them as part of its instructions, and acts without the user ever opening the invitation or seeing the Word document.How exposed is the organization to such an attack scenario?The numbers speak for themselves. According to Snyk’s ToxicSkills study, of the 3,984 AI agent skills examined, 36% were found to contain vulnerabilities that enable malicious prompt injection. The researchers identified 1,467 different malicious payloads and more than 8,000 MCP servers that were exposed to the general public.These findings illustrate the danger of the “Lethal Trifecta,” a situation in which the same agent simultaneously has access to sensitive organizational information, such as payroll files; exposure to content from an untrusted source, such as an external document; and the ability to send information outside the organization.When this combination exists within the same agent, a successful attack is only a matter of time.The defense architecture required for the age of agentic AITo address this reality, uniform security solutions or passive blocking are not enough. According to the methodology we developed at Commit, a combination of phased implementation and comprehensive defense architecture is required.In the first stage, a tiered approval process should be defined for every agent based on its level of risk. These are low-risk, Level A, (read-only tools with no ability to write, that can be approved through self-service); write permissions/sensitive information, Level B, (tools such as workplace agents that require approval by a human); and autonomy or production environment, Level C, (agents that run plugins or operate without human involvement, requiring approval from the chief information security officer and advance attack-scenario exercises).Along with classification, the work environment must be protected by six layers of defense under a defense architecture, namely: governance (allowing lists for add-ons and strict management of extension marketplaces); identity and access management (separation of API keys and management of narrowly defined access scopes); capability isolation (strict separation to prevent the “Lethal Trifecta”: an agent that reads external content must not be granted access to sensitive information during the same session); real-time monitoring (deployment of a proxy to monitor all MCP calls and prevent data leakage through Data Loss Prevention); egress control (blocking outbound network traffic by default and allowing only specific domains); and sandbox (running agents inside an isolated container with no direct access to the host operating system).The real change now required from management teams is a shift in mindset, and the window of opportunity to make that shift has almost closed.Once an AI agent is understood to be an entity that operates within the organization with permissions and execution capabilities, the defense model must move away from naive attempts to block incorrect outputs and toward proactive, multilayered management of the supply chain.The writer is vice president of cybersecurity at Commit.Follow us on Google
When AI becomes a double agent - opinion
Full Article
Original Source
Read the full article at Jpost →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.