When AI Agents Go Rogue: Agent Session Smuggling Attack in A2A Systems

Author: Jay Chen, Royce Lu Published: October 31, 2025 Source: https://unit42.paloaltonetworks.com/agent-session-smuggling-in-agent2agent-systems/ Summary Palo Alto Networks’ Unit 42 details “agent session smuggling,” an attack technique against multi-agent systems that communicate over the Agent2Agent (A2A) protocol. A malicious or compromised remote agent abuses the stateful, multi-turn nature of an active A2A session to covertly inject extra instructions … Read more

A Fake Bug Report Hijacks Your AI Coding Agent – and Nothing Catches It.

Author: Ron Bobrov, Barak Sternberg, Nevo Poran Published: June 9, 2026 Source: https://tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/ Summary Researchers at Tenet Security describe “Agentjacking,” an indirect prompt-injection attack class in which a malicious error event is planted in a victim’s Sentry error-tracking project and later read by an AI coding agent. Because the agent cannot distinguish data it retrieves … Read more