Thousands of malicious AI skills found capable of stealing data, running malware
Overview
Researchers at ESET have identified over 25,000 potentially malicious AI skills among nearly 900,000 analyzed. These skills, which enable AI agents to perform various tasks online, can be exploited by attackers to steal sensitive data, execute malware, or alter the behavior of the AI systems. This discovery raises significant concerns about the security of AI tools, as they could be manipulated to harm users or systems. The findings highlight the need for vigilance in monitoring AI skills and ensuring that they are secure, as the misuse of these capabilities can lead to serious data breaches and other cybersecurity incidents.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: AI skills and agents
- Action Required: Users should regularly review and verify the AI skills they enable, ensuring they come from trusted sources.
- Timeline: Newly disclosed
Original Article Summary
AI agents can browse the web, use external tools, execute commands, and perform tasks on behalf of users. Many rely on skills that define how they interact with services and data. Malicious skills can abuse those capabilities to steal data, execute malware, or manipulate an agent’s behavior, according to the H1 2026 ESET Threat Report. Malicious AI skills expand the attack surface An analysis of nearly 900,000 AI skills identified more than 25,000 suspicious skills … More → The post Thousands of malicious AI skills found capable of stealing data, running malware appeared first on Help Net Security.
Impact
AI skills and agents
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should regularly review and verify the AI skills they enable, ensuring they come from trusted sources. Organizations may also need to implement stricter controls on AI skill deployment and usage.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware.