[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-new-system-blocks-ai-agent-hijacking-by-checking-actions-not-attacks":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},10626,"new-system-blocks-ai-agent-hijacking-by-checking-actions-not-attacks","New System Blocks AI Agent Hijacking by Checking Actions, Not Attacks","APEX enforces a pre-written authorization contract at the moment an AI agent acts, blocking malicious instructions hidden in tools, MCP servers, and skills.","A team of researchers has built a defense that stops AI agents from being hijacked by malicious instructions buried in the content they read.\n\nThe system, called APEX, works differently than most prompt-injection defenses. Instead of trying to recognize attack patterns across every tool, MCP server, or skill an agent might use, it polices one choke point: the moment the agent turns its internal reasoning into an actual action, like sending an email or running code. At that boundary, APEX checks two things against a pre-written authorization contract: is this action allowed, and does the information driving it come from a trusted source. If either check fails, the action gets blocked or exposed before it executes. Tested against 13 existing defenses, APEX hit 0% attack success on five of six benchmarks and 0.56% on the sixth, and held at 0% even when attackers adapted their approach.\n\nIndirect prompt injection is the sleeper threat of agentic AI: hide a command in a web page, PDF, or API response, and the agent that reads it may just follow orders. Most defenses chase the growing list of places an injection can hide. APEX bets that the number of things an agent is allowed to do is a shorter, more stable list than the number of ways to attack it.\n\nThat is a reasonable bet, but it only holds if the authorization contract is written correctly for every task in the first place, which is its own, very human, point of failure.","[\"ai-security\",\"prompt-injection\",\"llm-agents\",\"ai-safety\"]","2026-10-07T04:00:00.000Z","2026-10-08T23:43:46.641Z","2026-10-08T23:43:51.042Z","published",null,[],"security",[26,27,28,29],"ai-security","prompt-injection","llm-agents","ai-safety",[31],{"name":32,"url":33},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2610.06966",0,{"sections":36},[37,42,46,51,56,61,66,71,76,80,85,90,95,100],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",6486,"2026-10-07T18:45:00.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":45},"Security",910,"2026-10-07T19:53:42.000Z",{"name":47,"slug":48,"count":49,"latest_published_at":50},"Policy","policy",474,"2026-10-07T18:23:21.000Z",{"name":52,"slug":53,"count":54,"latest_published_at":55},"Deals","deals",453,"2026-10-07T23:58:31.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Hardware","hardware",222,"2026-10-07T21:19:54.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Science","science",186,"2026-10-06T21:20:39.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Consumer Tech","consumer-tech",174,"2026-10-07T17:41:41.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Software","software",113,"2026-10-07T18:10:00.000Z",{"name":77,"slug":78,"count":74,"latest_published_at":79},"Startups","startups","2026-10-07T23:36:57.000Z",{"name":81,"slug":82,"count":83,"latest_published_at":84},"Dev Tools","dev-tools",105,"2026-10-07T16:59:11.000Z",{"name":86,"slug":87,"count":88,"latest_published_at":89},"General","general",61,"2026-10-07T22:00:24.000Z",{"name":91,"slug":92,"count":93,"latest_published_at":94},"Gaming","gaming",56,"2026-10-07T12:00:00.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"Reviews","reviews",33,"2026-10-05T11:57:17.000Z",{"name":101,"slug":102,"count":103,"latest_published_at":104},"How-To","how-to",8,"2026-10-05T09:00:00.000Z"]