MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-24 · via Dark Reading

Agentic AI App Manus Vulnerable to Prompt Injection Attacks

Image via Dark Reading
Image via Dark Reading

A prompt-injection vulnerability was discovered in the AI application Manus, which is valued at $4 billion. The flaw allows attackers to manipulate the AI by injecting malicious instructions through external data. This highlights the need for rigorous security filters in AI applications that process external information.

Expanded Detail

Manus, an AI application valued at $4 billion, has been found vulnerable to prompt-injection attacks. The flaw lets attackers manipulate the AI by embedding malicious instructions within external data. This exposes a key weakness: AI systems that process outside information must guard against untrusted content overriding their intended behavior.

The discovery emphasizes the need for rigorous security filters in AI applications handling external data. Without such safeguards, even well-funded AI products remain susceptible to manipulation, underscoring a broader challenge in the cybersecurity landscape.

Context

This vulnerability could affect businesses and individuals relying on Manus for automated workflows, potentially leading to manipulated outputs or data exposure. If exploited widely, it may undermine confidence in AI tools that depend on external information. The incident could also push developers to adopt stricter security testing practices, though the ultimate impact hinges on how quickly fixes are deployed and adopted.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Dark Reading →
Related stories
WordPress zero-day under active attack as exploit chain moves to file writes · Cybersecurity
Roundcube Webmail Vulnerability Under Active Attack, Canadian Cyber Center Warns · Cybersecurity
Check Point rushes hotfix for critical management server flaw under active exploitation · Cybersecurity
WordPress Core CSRF bug enables remote code execution via theme preview · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'.” Browse more stories.