PleaseFix 研究提出一种针对智能体浏览器的通用攻击原语 HistoryFixing,把浏览历史变成攻击向量。攻击由 Stav 设计:用户访问恶意网站后,网站用攻击者控制的条目污染浏览器历史,进而污染浏览器 Agent 的上下文。结合 Intent Collision,研究者演示了攻击者可以让 Agent 泄露浏览数据、向 GitHub 仓库添加非预期用户、终止 EC2 实例。相关演示在 DEFCON 上展示,其中 Microsoft Edge 被用来演示泄露从未删除的浏览历史。
引用StAJect0r@StAJect0r
A new attack vector pwning all agentic browsers!
Using what? Yep, your fav browser history!
Introducing HistoryFixing! Visited our URL? Your browser history is pwned.
Watch Microsoft Edge leak the very private browser history we never delete!
See more below!
#DEFCON @defcon @mbrg0 @p1njc70r
The Register covered our SalesBleed research 🙌🏼
Here's a quick recap:
Salesforce's Agentforce read a lead that an attacker submitted through a public form, and treated the text inside it as instructions. Since the agent already had access to the Accounts table, the injection didn't need to escalate anything to read it.
Its output guardrail, a URL redactor, was bypassed due to a vulnerability, and once the link was printed by the agent and rendered, a DNS lookup sent the data to the attacker's server with no click required from the user.
The same entry point also let the agent reply in Slack threads without requiring user confirmation and without indicating who invoked the agent, turning it into an anonymous phishing bot.
None of this required a misconfiguration. It was the default setup.
Salesforce has now fully fixed the issues.
https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958
Mindgard 在 Amazon Kiro IDE 中发现一条数据外泄路径:攻击者控制的仓库内容被当作指令,诱导 Agent 读取本地敏感信息并写入 IDE 配置,最终由 IDE 自动发起网络请求把数据带出。测试针对 Windows 上的 Kiro IDE 0.7.45,在受信任与不受信任工作区中均复现。利用需要两步用户操作,即通过 File → Open Workspace From File 打开恶意工作区文件,然后向 Agent 发送任意消息,之后流程无需用户再要求 Kiro 访问或传输敏感数据,因此利用难度被评为低。Amazon 通过 HackerOne 验证了报告,并在 Kiro IDE 0.8.140 中修复;该提交获 40 美元 Amazon 商店礼品卡,CVE 资格仍在评估。