Monday , October 5 2026
Dialogflow

Critical GCP Dialogflow Vulnerability Allows Malicious Code Injection

A critical flaw in Google Cloud Platform’s Dialogflow CX lets attackers add harmful code to a company’s AI chatbot system. The flaw, called “Rogue Agent,” was revealed by Varonis Threat Labs. It could secretly steal conversations and allow big phishing attacks, needing just one edit permission to start.

GCP Dialogflow Vulnerability

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

All agents using Code Blocks in the same GCP project share the same Cloud Run execution environment, and researchers found that a key file, code_execution_env.py, which runs Code Block logic via Python’s exec() function, was writable and lacked code restrictions.

An attacker took control of shared session data by changing this file. They could then mess with every agent’s tasks on the project. They only needed the dialogflow.playbooks.update permission, which can be limited to one agent, to set up Code Blocks and run any Python code.

Once the harmful code was saved, attackers could bring back the normal-looking settings in the console. This made the compromise hidden in Cloud Logging.

Varonis uncovered two compounding issues that amplified the risk:

VPC-SC bypass: Cloud Run’s unrestricted outbound internet access let attackers turn the execution environment into a covert data-exfiltration proxy, even when VPC Service Controls were enforced on the agent.

IMDS credential leakage: Exposure of the Instance Metadata Service allowed retrieval of access tokens tied to a Google-managed service account, violating isolation principles despite the account’s low privileges.

Rogue Agent (Source: Varonis)

Varonis inform Google about the flaw in November 2025. Google released a first fix in April 2026 and completely fixed the issue by June 2026. There were no reports of it being used in attacks before the update.

Rogue Agent is now part of a list of AI-platform flaws that Varonis has shared. This follows Reprompt in Microsoft Copilot Personal and SearchLeak in Microsoft Copilot Enterprise. The last one was fixed as CVE-2026-42824 and is marked with the highest severity level.

This trend shows that about 80% of Fortune 500 companies are now using AI agents, which increases the risk on cloud platforms.

Google and Varonis suggest that organizations using Dialogflow CX with Playbook Code Blocks before the patch should do the following steps:

*Enable DATA_WRITE audit logs for the Dialogflow API and review past playbook update events for anomalies.
* Correlate suspicious updates with rare API access, unusual IP addresses, or atypical access times.
*Query Cloud Logging for failed requests and inspect
*protoPayload.status.message for exceptions tied to malicious Code Block logic.
*Manually review each agent’s Playbooks in the Dialogflow CX console to confirm only whitelisted Code Blocks are configured.

Check Also

CISA

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw …