[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-new-zero-trust-stack-blocks-ai-agent-signing-key-attacks":10,"sections":34},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":29,"feedback":33,"feedback_at":22,"cost_usd":33,"total_tokens":33},7834,"new-zero-trust-stack-blocks-ai-agent-signing-key-attacks","New Zero-Trust Stack Blocks AI Agent Signing Key Attacks","A new security architecture forces AI agents to get human approval before signing anything with a hardware key that wasn't already committed to in advance.","Researchers just showed that putting an AI agent's signing key in a hardware chip does not stop a malicious email from hijacking it.\n\nAI agents now sign git commits, certify documents, and attest release artifacts on behalf of their operators, and their private keys often sit in plaintext files, environment variables, or container memory that any process the agent can reach can read. One widely deployed agent framework reportedly leaked its keys this way after a single email injection. Moving the key into a hardware keystore (HSM, TPM, smart card) does not fix the underlying issue, the researchers argue, because once a signing session is open, the hardware still cannot tell a legitimate request from one an attacker slipped into content the agent read. Their fix is a five-layer zero-trust enforcement stack that checks every signing request against what the operator actually committed to in advance.\n\nTested against AgentDojo prompt-injection attacks on three injection-prone models across 144 trials, the stack cut the attack success rate from 18.1 percent to zero. It handled tool poisoning from a compromised MCP server, tested with MCPTox, the same way: hashing pre-committed payloads and escalating anything uncommitted to a human. That escalation rule is the real finding here - the system's safety never depends on catching a fake document, only on a human getting asked whenever nothing was locked in ahead of time.\n\nThe limits show up fast. A substitute document under an adversarially plausible name beat the semantic filter in every trial the researchers ran, which is really just a reminder that this only works as well as your naming conventions - and as often as you're willing to interrupt a human.","[\"ai-agents\",\"security\",\"prompt-injection\",\"cryptography\"]","2026-09-25T04:00:00.000Z","2026-09-26T01:24:41.940Z","2026-09-26T01:24:48.332Z","published",null,[],"security",[26,24,27,28],"ai-agents","prompt-injection","cryptography",[30],{"name":31,"url":32},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2608.06130",0,{"sections":35},[36,41,45,50,55,60,65,70,75,80,85,90,95,100],{"name":37,"slug":38,"count":39,"latest_published_at":40},"AI","ai",4527,"2026-09-25T16:31:14.000Z",{"name":42,"slug":24,"count":43,"latest_published_at":44},"Security",741,"2026-09-25T15:52:13.000Z",{"name":46,"slug":47,"count":48,"latest_published_at":49},"Policy","policy",390,"2026-09-25T16:24:59.000Z",{"name":51,"slug":52,"count":53,"latest_published_at":54},"Deals","deals",256,"2026-09-25T17:00:53.000Z",{"name":56,"slug":57,"count":58,"latest_published_at":59},"Hardware","hardware",185,"2026-09-25T15:00:22.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":64},"Science","science",140,"2026-09-25T11:55:23.000Z",{"name":66,"slug":67,"count":68,"latest_published_at":69},"Consumer Tech","consumer-tech",132,"2026-09-25T15:30:00.000Z",{"name":71,"slug":72,"count":73,"latest_published_at":74},"Software","software",88,"2026-09-24T23:06:55.000Z",{"name":76,"slug":77,"count":78,"latest_published_at":79},"Dev Tools","dev-tools",82,"2026-09-25T09:59:40.000Z",{"name":81,"slug":82,"count":83,"latest_published_at":84},"Startups","startups",76,"2026-09-25T18:33:59.000Z",{"name":86,"slug":87,"count":88,"latest_published_at":89},"Gaming","gaming",48,"2026-09-25T18:35:21.000Z",{"name":91,"slug":92,"count":93,"latest_published_at":94},"General","general",46,"2026-09-25T02:12:57.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"Reviews","reviews",30,"2026-09-24T20:07:31.000Z",{"name":101,"slug":102,"count":103,"latest_published_at":104},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]