Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Embed Commands in Emails to Exploit AI Systems

Hackers Embed Commands in Emails to Exploit AI Systems

Posted on July 29, 2026 By CWS

In a concerning new trend, cybercriminals are embedding hidden commands within everyday emails, documents, and online ads, aiming to exploit artificial intelligence (AI) systems designed to protect digital communications. These tactics, often invisible to human eyes, directly target AI mail agents to potentially manipulate their actions or expose sensitive data.

Hidden Commands Target AI Systems

Referred to as indirect prompt injection, this method turns AI assistants into unintended targets by embedding commands that appear innocuous to people but are interpreted as legitimate requests by AI systems. According to Proofpoint, discussions and sales of such techniques are growing on underground forums, indicating the development of tools to generate these hidden prompts, although widespread misuse has not yet been observed.

This shift is significant as AI increasingly oversees incoming emails, attachments, calendars, and web content. Cybercriminals seek to exploit this automation, adding complexity to traditional phishing and social engineering attacks. Proofpoint’s report, shared with Cyber Security News, highlights that while these tools are currently experimental, organizations should prepare for their potential use.

Mechanisms of Indirect Prompt Injection

Indirect prompt injection occurs when AI systems mistakenly interpret embedded instructions as legitimate commands during content processing. Unlike direct prompt attacks, where commands are entered into chatbots, this approach hides commands within content that AI agents automatically read. Examples include emails with invisible ‘white-on-white’ text, posing as standard communications while influencing AI reading agents.

Similarly, attachments, like PDFs or DOCX files appearing as ordinary documents, may contain concealed text that affects AI scanning tools. The threat level varies with the AI system’s permissions, becoming more severe if the AI can act independently without human approval.

Security experts advocate treating external content as untrusted, even in familiar formats, and suggest separating untrusted text from system instructions, limiting AI access, and requiring human verification for critical actions to mitigate risks.

Expanding Risk with Calendar Invites

Criminals are also crafting prompt-injection tools for calendar invitations, embedding malicious commands in event descriptions disguised as meeting agendas. Unlike past phishing tactics, AI agents may automatically process these invitations as part of routine work, echoing the risks of weaponized calendar files.

Proofpoint’s findings also reveal interest in embedding prompts in malicious ads and webpages, using elements like HTML or image alternative text that humans might overlook but AI systems would process.

Organizations are encouraged to assess AI tool integration with emails, files, calendars, and web content, applying access controls to protect sensitive data and actions. Employees should continue flagging suspicious communications, while security teams monitor evolving phishing strategies that combine traditional delivery methods with AI-targeted manipulation.

Though no large-scale campaigns using these techniques have been noted yet, the active development and marketing of related tools suggest attackers are preparing for a future where AI systems are integral to the attack landscape.

Cyber Security News Tags:AI assistants, AI exploitation, AI manipulation, AI systems, calendar phishing, cyber attacks, Cybersecurity, data protection, digital security, email security, indirect prompt injection, online threats, phishing threats, proofpoint research, security measures

Post navigation

Previous Post: AI Agent Breaches Highlight Security Risks at Hugging Face
Next Post: Flying Eagle Android RAT Found on 170 Servers

Related Posts

Hackers Scanning Cisco ASA Devices to Exploit Vulnerabilities from 25,000 IPs Hackers Scanning Cisco ASA Devices to Exploit Vulnerabilities from 25,000 IPs Cyber Security News
VirusTotal Simplifies User Options With Platform Access And New Contributor Model VirusTotal Simplifies User Options With Platform Access And New Contributor Model Cyber Security News
Microsoft CoSnitch Vulnerability Exposes Data Risks Microsoft CoSnitch Vulnerability Exposes Data Risks Cyber Security News
Oyster Malware as PuTTY, KeyPass Attacking IT Admins by Poisoning SEO Results Oyster Malware as PuTTY, KeyPass Attacking IT Admins by Poisoning SEO Results Cyber Security News
New FortiWeb 0-Day Code Execution Vulnerability Exploited in the Wild New FortiWeb 0-Day Code Execution Vulnerability Exploited in the Wild Cyber Security News
OneDrive File Picker Vulnerability Exposes Users’ Entire Cloud Storage to Websites OneDrive File Picker Vulnerability Exposes Users’ Entire Cloud Storage to Websites Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • BlueMoon Exploit Kit Targets Chrome and Windows Zero-Days
  • How AI Adoption Transforms Security Operations Centers
  • OpenAI Agents Implicated in RubyGems Attack
  • AI Agents Exploit RubyGems in Massive Package Upload
  • CISA Alerts on GitLab Vulnerability Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • BlueMoon Exploit Kit Targets Chrome and Windows Zero-Days
  • How AI Adoption Transforms Security Operations Centers
  • OpenAI Agents Implicated in RubyGems Attack
  • AI Agents Exploit RubyGems in Massive Package Upload
  • CISA Alerts on GitLab Vulnerability Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark