{"id":61220,"date":"2026-08-05T21:35:00","date_gmt":"2026-08-05T21:35:00","guid":{"rendered":"https:\/\/www.theregister.com\/a\/5283585"},"modified":"2026-08-05T21:35:00","modified_gmt":"2026-08-05T21:35:00","slug":"prompt-injection-isnt-the-bug-ai-agent-frameworks-are","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/","title":{"rendered":"Prompt injection isn&#8217;t the bug, AI agent frameworks are"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/5283628.jpg?imageId=5283628&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" class=\"ff-og-image-inserted\"><\/div>\n<p>Nearly a dozen flaws, some critical, in major AI agent frameworks that enterprises use to build apps reveal a security failure that extends beyond prompt injection &#8211; or any single model &#8211; according to Check Point researchers.<\/p>\n<p>\u201cOur research shows a deeper failure: in many agentic frameworks, prompt-controlled content can cross the boundary into trusted framework logic itself,\u201d Yarden Porat and Shahar Tal note in a write-up about a Wednesday Black Hat talk on post-injection exploitation across AI agent frameworks, which they also discussed with <span class=\"italic m-italic \" data-lab-italic=\"italic\">The Register.<\/span><\/p>\n<p>\u201cA bug in an agent framework isn&#8217;t a bug in one product &#8211; it&#8217;s a bug in the layer a whole category of AI apps runs on,\u201d Tal told us. \u201cAnd the agent needs no dangerous tools to be turned against you: reading the wrong document is enough. We\u2019re building this layer faster than we know how to defend it.\u201d\u2028<\/p>\n<p>The researchers spent a year trying to break various frameworks that enterprises use including LangChain, LangGraph, CrewAI, AutoGen, Microsoft Agent Framework, and Google ADK. And across these frameworks, the team found and disclosed 11 vulnerabilities.<\/p>\n<p>\u201cAlmost none of it was a completely new bug class,\u201d Tal said. \u201cThat&#8217;s insecure deserialization, server-side request forgeries, path traversals, use-after-free. These are bugs that we learned to fix 20 years ago, and they&#8217;re sitting underneath agents that now read your inbox, or update your database.\u201d<\/p>\n<p>These are old types of threats, and the model isn\u2019t the weak link, he added. The failure exists in the \u201cplumbing around the model, and we think this has been overlooked,\u201d Tal told us. \u201cThere\u2019s a lot of research going into prompt injection and defenses, which are important, but that\u2019s just the beginning.\u201d<\/p>\n<p>Defenders should assume <a href=\"https:\/\/www.theregister.com\/security\/2026\/07\/07\/github-ai-agent-leaks-private-repos-when-asked-nicely\/5267924\">prompt injection<\/a>, according to the researchers. The bug is what the framework does with the injection &#8211; and in these cases, the threat hunters found that the frameworks often fail to keep attacker-controlled content in the data plane. This allows it to influence trusted orchestration, memory, state, routing, and system instructions.<\/p>\n<p>For example, the duo found a critical checkpoint deserialization bug in Microsoft Agent Framework that led to remote code execution.<\/p>\n<p>\u201cAgents have checkpoints, which are a way for them to save their state or rewind to an earlier point,\u201d Tal explained.<\/p>\n<p>These checkpoints are saved snapshots of an agent&#8217;s state, or task progress at a specific moment, and they serialize data &#8211; such as conversation history &#8211; into persistent storage, so if an error occurs, the system reloads this saved state instead of starting from scratch.<\/p>\n<p>In this case, Check Point\u2019s team found an insecure deserialization issue where, via prompt injection, the agent loaded untrusted checkpoint data, and this could allow attackers to execute malicious code on the system. \u201cOne person&#8217;s message plants the payload, and then a different person rewinds their own session, which triggers the payload, and now the attacker has a shell on that server,\u201d Tal said.<\/p>\n<p>Microsoft recognized the researchers\u2019 findings, paid a $10,000 bug bounty and fixed the issue. But because the framework wasn\u2019t a generally available product when Check Point found the flaw, Microsoft did not issue a CVE.<\/p>\n<p>Microsoft told us that it appreciated the researchers reporting the vulnerability. \u201cWe have released protections to harden the Agent Framework and prevent the concrete exploitation path demonstrated in the proof of concept,\u201d a spokesperson told <span class=\"italic m-italic \" data-lab-italic=\"italic\">The Register<\/span>. \u201cIn addition, we <a href=\"https:\/\/protect.checkpoint.com\/v2\/r01\/___https:\/\/github.com\/microsoft\/agent-framework\/blob\/main\/python\/packages\/core\/agent_framework\/_workflows\/_checkpoint_encoding.py___.YzJ1OndlY29tbXVuaWNhdGlvbnM6YzpvOjViZDY0NDFiNWViMjFlNWU0ZGQ5NTExMmM1OTM4YzNkOjc6NTAwOTowMTdhMjY4MWRmOTNhNzU3MjFjZjUxYWNjOTg1MDJmMjQ0M2VkODYxNTczMzgxOTc1YmQ2NGYwMmMyZDc3YTgzOmg6VDpG\" rel=\"nofollow\">updated<\/a> the specific checkpoint file with additional language to define the security boundary.\u201d&nbsp;<\/p>\n<p>The duo also found flaws in Google ADK (agent development kit). However, Google responded differently, the researchers told us, and did not completely fix the vulnerability or issue a CVE.<\/p>\n<p>\u201cADK ships a built-in development assistant that can write files, and it stays reachable over the HTTP API even though it is hidden from the app listing,\u201d Porat told us.&nbsp;<\/p>\n<div data-element-guid=\"afe083ca-6701-48e9-9bd8-f8827dd7fb42\" class=\"lab4 column articleList layout_vertical imageLayout_left small-12 large-12 small-abs-12 large-abs-12 abs_grid_12 grid-vas-start mobile-grid-vas-start\">\n<div class=\"content border_width_0 border_width_mobile_0 border-radius-48 border-radius-mobile_48\">\n<h2 class=\"article-list-title t19 font-RobotoCondensed\">MORE CONTEXT<\/h2>\n<\/p><\/div>\n<\/div>\n<p>To break this trust boundary, an attacker opens a session, asks ADK to write an agent whose Python code runs at import time, and then asks the server to run the agent, he explained. The server then imports the file and executes the attacker\u2019s code.&nbsp;<\/p>\n<p>\u201cThere is no authentication on that API by default, and adk deploy cloud_run publishes the same API, so on a default Cloud Run deployment it is reachable without credentials,\u201d Porat said. \u201cFrom there it reaches the environment&#8217;s API keys and the container&#8217;s Google Cloud service account.&#8221;<\/p>\n<p>Google did not respond to <span class=\"italic m-italic \" data-lab-italic=\"italic\">The Register\u2019s <\/span>inquiries. But according to Check Point, Google initially deemed the issue not a bug.&nbsp;&nbsp;<\/p>\n<p>\u201cWe argued the consequence rather than the mechanism: code execution on that container reaches the environment&#8217;s API keys and the container&#8217;s Google Cloud service account, which is secret theft, not a developer inconvenience,\u201d Porat said.&nbsp;<\/p>\n<p>Google ultimately paid a $3,133.70 bounty and issued a partial fix, we\u2019re told.<\/p>\n<p>In total, the bug hunters received $17,133.70 in rewards for their efforts.<\/p>\n<p>And this isn\u2019t a story about one vendor or framework doing a \u201cparticularly bad job,\u201d Tal said. \u201cIf one was an outlier, this would be a story about that one vendor,\u201d he added. \u201cOur finding is that the same bug classes turn up in all of them.\u201d \u00ae<\/p>\n<p> <img decoding=\"async\" src=\"https:\/\/image.theregister.com\/?imageId=5283628&#038;width=800\">READ MORE <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/05\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/5283585\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Check Point researchers tried to break the frameworks enterprises use to build AI apps. Now they&#8217;re telling Black Hat attendees what they found READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[307],"class_list":["post-61220","post","type-post","status-publish","format-standard","hentry","category-the-register","tag-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Prompt injection isn&#039;t the bug, AI agent frameworks are 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Prompt injection isn&#039;t the bug, AI agent frameworks are 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-05T21:35:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/image.theregister.com\/5283628.jpg?imageId=5283628&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Prompt injection isn&#8217;t the bug, AI agent frameworks are\",\"datePublished\":\"2026-08-05T21:35:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\\\/\"},\"wordCount\":889,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/image.theregister.com\\\/5283628.jpg?imageId=5283628&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"keywords\":[\"Security\"],\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\\\/\",\"name\":\"Prompt injection isn't the bug, AI agent frameworks are 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/image.theregister.com\\\/5283628.jpg?imageId=5283628&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"datePublished\":\"2026-08-05T21:35:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\\\/#primaryimage\",\"url\":\"https:\\\/\\\/image.theregister.com\\\/5283628.jpg?imageId=5283628&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"contentUrl\":\"https:\\\/\\\/image.theregister.com\\\/5283628.jpg?imageId=5283628&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Prompt injection isn&#8217;t the bug, AI agent frameworks are\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Prompt injection isn't the bug, AI agent frameworks are 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/","og_locale":"en_US","og_type":"article","og_title":"Prompt injection isn't the bug, AI agent frameworks are 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-08-05T21:35:00+00:00","og_image":[{"url":"https:\/\/image.theregister.com\/5283628.jpg?imageId=5283628&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Prompt injection isn&#8217;t the bug, AI agent frameworks are","datePublished":"2026-08-05T21:35:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/"},"wordCount":889,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/#primaryimage"},"thumbnailUrl":"https:\/\/image.theregister.com\/5283628.jpg?imageId=5283628&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","keywords":["Security"],"articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/","url":"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/","name":"Prompt injection isn't the bug, AI agent frameworks are 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/#primaryimage"},"thumbnailUrl":"https:\/\/image.theregister.com\/5283628.jpg?imageId=5283628&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","datePublished":"2026-08-05T21:35:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/#primaryimage","url":"https:\/\/image.theregister.com\/5283628.jpg?imageId=5283628&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","contentUrl":"https:\/\/image.theregister.com\/5283628.jpg?imageId=5283628&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/prompt-injection-isnt-the-bug-ai-agent-frameworks-are\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.threatshub.org\/blog\/tag\/security\/"},{"@type":"ListItem","position":3,"name":"Prompt injection isn&#8217;t the bug, AI agent frameworks are"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61220","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=61220"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61220\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=61220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=61220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=61220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}