At Black Hat USA 2026, a major security concern took center stage with nearly a third of presentations focused on AI security 35 out of 121 briefings. But the real shocker wasn’t the number of talks. It was the fact that four confirmed sessions revealed attacks on the very foundations AI agents rely on: their runtime environments, cloud services, compute clusters, and even the tools meant to exploit them.
Check Point Research’s session, "No Tools Required: Post-Injection Exploitation Across AI Agent Frameworks," highlighted a new perspective. Researchers Yarden Porat and Shahar Tal exposed serious flaws inside popular AI frameworks like LangChain, CrewAI, AutoGen, and Semantic Kernel. Vulnerabilities hide in critical parts such as memory management, planning cycles, serialization, and orchestration processes. Attackers don’t even need direct access to the tools. Manipulated content alone can breach trust boundaries and commandeer agents by exploiting the framework’s core logic.
This flips traditional AI security on its head. Instead of focusing on restricting the tools agents can access like filtering outputs or setting prompt limits defenses must shift toward protecting the frameworks themselves. If the infrastructure that runs these agents is inherently flawed, no amount of tool control will prevent exploitation.
Adding to the urgency, NVIDIA researchers Bar Lanyado and Eliya Cohen presented a new fine-tuned open-source model called WASP-OS, boasting a 56% success rate in exploiting AI agents. It competes with top models like GPT-4o and Claude but operates at a fraction of the cost 70 to 125 times cheaper and preserves privacy by running without cloud APIs. This development means AI agent attacks are becoming both more affordable and harder to detect, creating a significant challenge for defenders trying to secure AI infrastructure.
These insights suggest AI agent exploitation is evolving into a specialized field with its own techniques and strategies. Securing these systems demands a fundamental rethink of where vulnerabilities lie not just in applications or tools, but deep within the frameworks and infrastructure powering AI agents.
This material is informational and not financial advice.



