Realtime AI News
Popular AI agent Manus could be hacked with a single email, researchers show
Security researchers at Salt Labs bypassed Manus's prompt-injection defenses by hiding a JSFuck-obfuscated instruction inside an email, achieving arbitrary JavaScript code execution in the agent's server-side runtime. The flaw has since been patched, but the team warns that agents with broad third-party access remain exposed to similar attacks.
Security researchers at Salt Labs say they found a way around the guardrails protecting Manus, a popular AI agent. By planting a hidden prompt inside an ordinary email, they got the agent to execute arbitrary JavaScript on the server side. TechRadar reports the flaw has since been fixed.
Prompt injection has plagued AI agents since their earliest days. The root problem is that models cannot reliably separate instructions from the data they are asked to process: ask an agent to summarize an email, and a second prompt buried in that email may run alongside your own request.
Salt Labs tested Manus's integration with Gmail. They sent an email containing a concealed prompt; Manus flagged the content as executable and warned its owner, but it still tried to act on the instructions, stopping only when a safety mechanism detected the danger.
That raised a sharper question: what if the agent never recognized the prompt as malicious? The team tried Base64 encoding and having the agent decode and run payloads with Python, and eventually found success with JSFuck, an unusual JavaScript obfuscation method that uses a very limited character set and is rarely seen in modern environments.
They embedded a simple JSFuck-encoded payload that would execute a basic JavaScript statement. “The intent appeared to be content decoding and rendering. However, this effectively executed arbitrary JavaScript code in a server-side environment,” the researchers wrote. The payload ran and produced the expected output. Untrusted email content had become executable code, running inside the agent's runtime. Manus did notify the owner — but only after the code had already executed.
Salt Labs says it disclosed the issue responsibly through a bug bounty program, and that it has since been resolved and is no longer exploitable. But the broader lesson, the team argues, is that if researchers can get around Manus's guardrails, criminals can too — perhaps not with JSFuck, but human creativity has no bounds.
The attack surface is growing. Menlo's 2026 State of Consumer AI report, cited by TechRadar, found that consumers have already given agents access to their email (36%), web browsers (33%), messaging apps (31%), cloud storage (29%) and calendars (27%), with health apps (23%) and financial accounts (20%) increasingly in the mix.
Salt Labs's warning is aimed at every enterprise deploying agents: guardrails that inspect prompts and model behavior are necessary but not sufficient, and security has to cover what an agent actually does across the tools, APIs and systems it can reach. As long as a single injection can escalate into code execution, handing an agent the keys to your inbox remains a calculated risk.
Why it matters
Agents wired into email, calendars and cloud storage can turn a routine prompt injection into real code execution once their guardrails fail. Enterprises need to audit what an agent does across its connected tools, not just what it reads.
Nearby Updates
All10/03, 01:31
Google Launches Gemini 4 Argon With 1 Million Token Output Window, Taking On GPT-6 Astra
Google has launched Gemini 4 Argon, a new model billed as offering a 1 million token output window and positioned as a direct challenger to OpenAI's GPT-6 Astra. The framing shifts attention from context length to the scale of a single generation, though the report offers no pricing, availability or benchmark details.
10/03, 01:44
Anthropic commits $100 million to train 10,000 enterprise AI engineers
Anthropic says it will commit $100 million to train 10,000 enterprise AI engineers. The pledge targets the talent gap that keeps large organizations from putting AI into production workflows.
10/03, 00:15
OpenAI publishes a practical guide to building with the GPT-6 family
OpenAI has published a practical guide for startups working with its GPT-6 family, covering model selection, tuning reasoning effort, improving prompts and skills, coordinating tools, and preparing workflows for production. The guide launches no new model, but it signals the company's push to move GPT-6 from demos into production deployments.
10/03, 00:00
OpenAI dismisses three employees over sensitive information
OpenAI has dismissed three employees in connection with sensitive information, according to a Taipei Times report carried through Google News. The report does not disclose the roles involved or the nature of the information at issue.