Security News

Cybersecurity news aggregator

MEDIUM Vulnerabilities Dark Reading

Claude Flaw Automatically Sends Malicious Prompts to AI Agents

  • What: Vulnerability in Claude AI allows prompt injection
  • Impact: Users may be exposed to malicious prompts
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources VULNERABILITIES & THREATS CYBER RISK THREAT INTELLIGENCE ENDPOINT SECURITY NEWS Claude Flaw Automatically Sends Malicious Prompts to AI Agents When combined with another exploit, the "PromptFiction" vulnerability, which has been fixed, could have enabled an end-to-end attack on a targeted system. Elizabeth Montalbano,Contributing Writer July 15, 2026 5 Min Read SOURCE: RALF LIEBHOLD VIA ALAMY STOCK PHOTO A vulnerability in Anthropic's Claude Desktop application could have allowed attackers to automatically submit malicious prompts to the AI assistant with a single click and without any interaction from a user at all. Anthropic already has fixed the flaw, but it demonstrates the next level of prompt injection attacks that are possible using AI agents. Researchers from Oasis Security discovered the flaw, dubbed "PromptFiction," which — when combined with a previous trio of flaws they found in Claude, dubbed "Claudy Day" — could have enabled an end-to-end attack on the targeted system, according to a report published Wednesday. LOADING... This would facilitate "silent exfiltration of the user's previous conversations and, when Anthropic's official Filesystem Server is installed, read/write access to local files, persistence, and ultimately remote code execution on the victim's machine," Elad Luz, research lead at Oasis, wrote in the report. Related:Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes PromptFiction demonstrates a prompt injection attack that doesn't require a key aspect of previous examples of this class of threats within an AI agent — a user hitting the Enter or Send button to submit a malicious prompt unknowingly. What Oasis found is that Claude Desktop registers a custom URI scheme, "claude://," and that a crafted "claude://" link automatically opens the desktop application and submits a prepared prompt to the agent. This eliminates the "send" action and thus there is "no opportunity for the user to review it," according to the report. "A single click on a link, in a browser, a chat message, a document, or a search result, is enough to put attacker-authored instructions in front of the agent and have them executed," Luz wrote. LOADING... Claudy Day, in contrast, demonstrated a different form of prompt injection in which an invisible prompt could be smuggled into a claude.ai chat through a pre-filled URL that still required the user pressing Enter to send the prompt to the AI assistant. Duplicate Discovery for PromptFiction Oasis reported its finding to Anthropic through the AI company's Responsible Disclosure Program and the flaw has been fixed in Claude Desktop version 1.1.2321; users should ensure they are running that release or later so they are not at risk. Oasis acknowledged that its PromptFiction report was a duplicate, as another researcher independently reported the same issue to Anthropic but chose not to publish their findings. "We thank them for their work and make no claim to sole discovery," Luz wrote. The responsible disclosure of PromptFiction and its rapid remediation is "a good outcome," even if the flaw itself could have "escalated from data exposure to potential code execution on the victim's machine," observes Randolph Barr, chief information security officer (CISO) at API security and bot management provider Cequence Security. Related:Fresh ATM Crypto Software Bugs: Jackpot or Bust? Moreover, the fact that the flaw existed at all demonstrates how AI is compressing the race between researchers and attackers to discover security gaps in emerging technology, Barr says. "The same models that help defenders are helping attackers find and weaponize flaws faster, which means the window between a vulnerability existing and a patch shipping is exactly where organizations are most exposed," he says. Indeed, this is where the industry has to adapt to the rapid pace of AI, Luz says. "The old model of a person carefully reviewing every release doesn't survive contact with this velocity," he tells Dark Reading. The best way to secure AI agents and other applications is by "turning the same AI tools back onto the problem, using them to review and secure what we ship as fast as we ship it," he says. The Full PrompFiction Attack Chain A PromptFiction attack begins with a victim clicking a malicious claude:// link delivered through virtually any medium, including a website, document, chat message, email, or search result. This is similarly to how a Zoom or email invite opens its application on a user desktop, according to Oasis. Related:Microsoft Reins in RoguePlanet Zero-Day Threat Instead of simply opening Claude Desktop, however, the link opens an application that immediately launches a new conversation and automatically submits an attacker-crafted prompt without requiring the user to review or approve it. "Custom URI schemes are convenient: They let a website or another app deep-link into a desktop application," Luz wrote. "They are also a classic source of risk, because the launching context (a web page, an email, a chat) is frequently attacker-influenced, and the receiving application often trusts the arguments more than it should." To reduce suspicion, the prompt is padded with benign text to exploit Claude's message-folding behavior, hiding the malicious instructions below the visible portion of the conversation, according to Oasis. Users see only an innocuous request unless they expand the collapsed message. Once executed, the hidden prompt instructs Claude to perform actions on the attacker's behalf — a reliable prompt-injection attack on its own. However, as previously described, when combined with Claudy Day flaws, the injected instructions can silently perform other malicious activities, including pulling up a user's private conversation history, source code, internal documents, or even executing remote code, according to Oasis. Staying Ahead of AI Agent Risk With the capabilities of AI accelerating at an unprecedented rate, it seems like it was only a matter of time before AI agents started finding ways around the built-in guardrails of their systems. PromptFiction is an example of that, says John Gallagher, vice president at automated IoT cyber hygiene provider Viakoo. "Organizations should see AI agents as another form of 'shadow IT,' similar to operational technology (OT) and IoT devices that are operated outside of IT" because they often have privileges but also they can enable lateral movement into corporate networks and storage systems, he says. Defenders have some work to do in terms of AI governance, which "is clearly lacking in this area," Gallagher says. "Non-human identity management is in its early stages, and this is an example of AI getting ahead of the proper controls around it." Rather than focusing exclusively on individual vulnerabilities, then, defenders should build security controls around the agents themselves, Barr advises. "Put an inspection and policy layer between AI agents and everything they talk to," he says. This, in practice, means monitoring and governing agent API traffic to detect or block suspicious data transfers, restricting which destinations and API credentials agents can access, detecting anomalous behaviors, and maintaining an inventory of AI agents, MCP servers, and plug-ins deployed across the environment, experts say. About the Author Elizabeth Montalbano Contributing Writer Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program More Webinars You May Also Like VULNERABILITIES & THREATS Exchange Flaw Lets Attackers Spoof Any Email Address by Alexander Culafi JUN 09, 2026 VULNERABILITIES & THREATS Cheap Hardware Module Bypasses AMD, Intel Memory Encryption by Rob Wright NOV 25, 2025 VULNERABILITIES & THREATS Patch Now: Microsoft Flags Zero-Day & Critical Zero-Click Bugs by Jai Vijayan NOV 11, 2025 VULNERABILITIES & THREATS Microsoft Issues Emergency Patch for Critical Windows Server Bug by Rob Wright OCT 24, 2025 Editor's Choice PERIMETER 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems byAlexander Culafi JUL 14, 2026 4 MIN READ CYBERSECURITY OPERATIONS 'Yellow Teams' Are Defining the Future of AI Security byNate Nelson JUL 13, 2026 6 MIN READ CYBERSECURITY OPERATIONS Why Identity Security Is Your Cyber Career Entry Point byKristina Beek JU

Share this article