Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Your AI Transformation Needs Runtime Protection for the Whole Agentic Estate

AI Detection and Response (AI-DR), also called AI runtime security, is quickly becoming a must-have. Prompt injection, jailbreaks, and data leakage are real, and the prompt is often where attacks begin. But the prompt is only the first hop. In an agentic enterprise, a single instruction can trigger activity well beyond the LLM, all the way to your business systems and data.

Securing Your AI Agents: Native AI Detection and Response Across the Full Agentic Path

Enterprises are deploying AI agents at scale, and those agents are taking real business actions. Through LLMs, MCP servers, and APIs, they move money, access patient records, modify code, and send emails. The attack surface has fundamentally shifted, but most security programs are still focused on what an AI says rather than what it does.

How We Hijacked an AI Agent With a Single Email

Salt Labs found that the agentic AI platform Manus could be hijacked with a single email. By hiding malicious instructions inside an ordinary message, researchers got Manus to execute malicious code and, from there, reach the email, cloud storage, and code repository accounts a user had connected to it. The full attack required nothing from the victim beyond asking Manus to check their inbox. No stolen password, no clicked link.

When a Security Guardrail Detects the Attack and Still Can't Stop It

Salt Labs recently showed that a single email could hijack the AI agent platform Manus and reach a victim’s connected accounts. The full technical breakdown, with complete evidence, payloads, and screenshots, is in our research team’s write-up, and Dark Reading first reported the finding in an exclusive. This post is the shorter version: what the finding means and what it tells every organization now deploying AI agents. For the full technical detail, read the Salt Labs research blog.