Back Feeds.4Sysops AutoJack exploit chain allows web-enabled AI agents to trigger host
Microsoft researchers have identified a critical exploit chain named AutoJack that allows malicious web content to compromise the host machine running an AI agent. The vulnerability specifically targeted AutoGen Studio, a prototyping interface for multi-agent systems, by abusing its trusted local access. By chaining three separate weaknesses, an attacker can bypass localhost security boundaries to execute arbitrary commands under the developer's account. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
