Artificial Intelligence

AI Agents, Zero-Click Attacks: The Next Cybersecurity Threat

AI agents can read websites, emails and documents and take actions independently, creating new opportunities for prompt injection and zero-click attacks while forcing organisations to rethink permissions, oversight and cybersecurity boundaries.

Written By : Market Trends

By: Mandar Patil, EVP, Cyble

Overview:

  • AI agents can turn ordinary websites, emails and documents into potential attack vectors.

  • Prompt injection can manipulate agents into performing actions users never requested.

  • Least privilege, approval controls and security testing can reduce emerging agentic risks.

Human interaction has been a key element in the success of cyberattacks for years. A victim was required to click on a malicious link, open an attachment, download a file, or enter credentials. But zero-click attacks prove that this is not always the case. The question now is whether AI tools are making zero-click attacks easier, as they are now becoming more adept at answering questions, surfing websites, and taking actions on behalf of users.

When Data Becomes an Attack Vector

Today's AI agents can communicate with websites, emails, documents, apps, and digital tools.

Indirect prompt injection is a concern. Attackers can embed malicious instructions within content that an AI agent is processing, such as a website, email, document, search result, or data returned from another tool.

They can request an agent to summarise emails, research a topic, or organize information. In that task, the agent may come across content controlled by the attacker. If it treats the embedded instruction as valid context, it might execute an action the user did not ask for.

OpenAI has termed this growing issue “social engineering,” in which external content attempts to trick an agent into performing an action that is not in the user's instructions.

Why Zero-Click Becomes Possible

The difference between an attack and an AI attack is agency. A traditional application will wait for a user to make a decision. An AI agent can be programmed to make intermediate decisions.

This means that a malicious webpage doesn't have to convince a person to click. It may only have to affect an agent that is already surfing the page and has permission to communicate with another service.

The risk is heightened when the agent has access to private information, authenticated accounts, internal documents, communication tools, or system functions. If the attacker already has legitimate access, he doesn't have to penetrate each security level.

Microsoft has illustrated how vulnerabilities in agent frameworks can enable prompt injection to breach the boundary and lead to code execution, highlighting the potential for natural-language inputs to pose a security risk when models are integrated with powerful tools.

The Problem Goes Beyond Prompts

Security researchers are also looking at attacks in which malicious information is presented as legitimate. This can be used to control an agent without issuing a clear command such as “ignore previous instructions.”

Agent data injection is an attack technique that researchers have demonstrated can affect web and coding agents by allowing attacker-controlled data to influence the system, potentially leading to unintended actions.

This reveals a basic problem with agentic systems. Language models are meant to understand context, while security systems are meant to assert authority.

AI Can Strengthen Attacker

Threat actors can use AI to research targets, analyze technical content, develop convincing content, modify malicious code, and automate aspects of an attack chain.

The threat is not just that AI can write malicious code. It can reduce the workforce required to link reconnaissance, manipulation, decision-making, and execution.

Building Safer AI Agents

AI agents are not just another tool for productivity. They should be considered systems capable of interacting with sensitive environments and performing consequential tasks.

The first principle should be least privilege. An agent should not be able to send messages, access credentials, execute commands, or transfer files unless those capabilities are necessary for its assigned task.

Second, organizations should establish clear boundaries between instructions and external information. Websites, emails, documents, search results, and tool outputs should be treated as potentially untrusted inputs.

Third, there should be meaningful approval controls for high-impact actions. Human oversight should be used when an action might reveal sensitive information, alter security settings, or impact critical systems.

Last but not least, there should be ongoing security testing and comprehensive logging. Security teams should be able to determine what an agent saw, what tools it used, what decisions it made, and what happened.

Not all attacks will be zero-click with the advent of AI. It alters the economics of exploitation, however. If software can read, reason, and act on its own, then there's another target for the attackers to manipulate.

The next generation of cyber defense can no longer be just about shielding people from malicious clicks. It also needs to shield AI agents from harmful instructions that appear as regular information.

The next big security question in the agentic era might not be, “What did the user click?” Perhaps, “What was the AI authorized to do?”

This means that security boundaries need to consider what agents read, not just what users submit or approve before taking action.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp

Crypto Market Live Today: Bitcoin Holds Near $78K as Rate Hike Fears Weigh on Market

Crypto Prices Today: Bitcoin Holds Near $77,500 as Solana, Hyperliquid Lead Gains After Jackson Hole Selloff

Crypto Trading in September 2026: Bitcoin, Altcoins and AI Trading Trends to Watch

USD 75 Million Crypto Fundraising Exemption? Here’s What the SEC is Proposing

5 Top Meme Coins in 2026: Which Crypto Could Make the Next Big Jump in September?