Manus Ran Email Code Before Warning the User in Salt’s Test

Salt's Manus test: code ran before warning; flaw resolved.
Artificial intelligence, local AI, agents, tooling and AI security.

Salt's Manus test: code ran before warning; flaw resolved.

Self-hosted gateway fix available.

Prioritise AI service fixes by verified deployment exposure.

Give findings and patches an accountable review path.

Two LightLLM helper services can accept unsafe network input outside the model API. Check multimodal and profiling nodes, their live ports and their network boundaries.

A fixed MCP Python SDK release is only part of the repair for unattended OAuth clients. Pin the issuer, rebind saved registrations and assess possible credential exposure.

In an OpenAI test, a routine email reply carried a prompt injection into the outgoing message. The result was simulated, but the path between agents deserves a real-world test.

A malicious CRM lead could cross into Agentforce and emerge as a trusted Slack reply without showing who triggered it. Salesforce has changed the defaults.

Check Point used a shared internal package service to pass hidden tasks between separate ChatGPT accounts. In its demonstration, the victim saw a normal answer while Gmail data crossed the boundary.

Anthropic says a Russia-linked espionage operator used AI to monitor detections and keep rebuilding malware until it was no longer detected. The attack cycle, not a single hash, is now the defensive problem.