Security News

Cybersecurity news aggregator

HIGH Vulnerabilities Dark Reading

Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft

The "Rogue Agent" vulnerability was a critical permission boundary flaw in Google Cloud's Dialogflow CX platform that allowed attackers to exploit the Code Blocks feature by updating a single permission (`dialogflow.playgroups.update`), enabling persistent code injection to exfiltrate conversations and conduct phishing campaigns. The underlying issue has been fully mitigated by Google, requiring no customer action.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources APPLICATION SECURITY СLOUD SECURITY IDENTITY & ACCESS MANAGEMENT SECURITY DATA PRIVACY NEWS Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft Varonis reported the flaw to Google in late 2025 and it has been addressed, but it reminds defenders to take a fresh look at their AI Infrastructure security. Alexander Culafi,Senior News Writer,Dark Reading July 7, 2026 3 Min Read SOURCE: RICHARD DRURY VIA GETTY IMAGES Google recently fixed a vulnerability that would have enabled an attacker to seize data from AI agents and chatbots built with one of Google's flagship AI tools. Varonis researchers this week disclosed "Rogue Agent," a permission boundary issue in Google Cloud Platform's Dialogflow CX AI platform that Varonis Threat Labs describes as a "critical vulnerability." According to a research blog post, Rogue Agent would have "allowed attackers to exploit the Code Blocks feature to inject persistent malicious code into the Dialogflow agents' pipeline, silently exfiltrating conversations and conducting large-scale phishing campaigns." LOADING... Exploitation required updating only a single permission — dialogflow.playbooks.update — on one Dialogflow agent to exploit. The vulnerability has been addressed, and no customer action is required. Varonis reported the issue to Google in November 2025, which issued an initial patch in April before fully resolving the issue last month. All affected components were fixed. Related:Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS A Google Cloud spokesperson tells Dark Reading that the company appreciates the efforts of researchers like those at Varonis that disclose through Google's Vulnerability Reward Program. "The underlying issue has been fully mitigated, and we have no known indication of customer compromise," the spokesperson says. A Single Permission Grants Access to a Host of Data Dialogflow CX is used to build enterprise-grade AI agents and bots. Think customer support systems, financial services bots, healthcare chatbots, and other use cases that handle sensitive customer data. The tool allows developers to add "Code Blocks," pieces of custom Python code that can process user input, manipulate data, and call APIs. Code Blocks run inside Google's Cloud Run environment — used for running containerized applications — and have public network egress by default, the spokesperson says, "meaning they can initiate outbound connections to the Internet and effectively communicate across data perimeters and break zero-trust architectures." All Dialogflow agents using Code Blocks in a single GCP Project share the same Cloud Run execution by default, and because this is managed by Google, the user has no direct visibility into the execution environment. This makes rogue agents hard to detect in successful attacks, as important parts of the attack happen outside the user's purview. The other important component is Playbooks, a building block inside Dialogflow CX that helps customers build agents using natural language and generative AI. Related:New Initiative Tackles Security for End-of-Life Open Source Software If an attacker got the ability to update the Playbooks Code Block for a single agent in a customer's environment (such as via compromising a privileged employee account), they could use a Code Block to download and overwrite an internal execution file with a malicious version, which becomes part of the execution pipeline for future conversations. In addition to accessing conversation history and session data, the attacker could, for example, insert a phony reauthentication prompt into a conversation naturally to get the victim to divulge legitimate credentials. While credentials (i.e., initial access) would have been required for exploitation, the dialogflow.playbooks.update permission required to execute an attack could be granted at the project level, meaning this was by no means an attack limited to high-level administrators. Don't Forget About Securing AI Infrastructure Although organizations are no longer at risk of the attack based on existing evidence, Varonis advised organizations to review logs for Playbook updates, run a query for failed user requests (the failure may have been triggered through malicious logic), and manually review Code Blocks for unauthorized code. Tamir Yehuda, cloud security research team leader at Varonis, tells Dark Reading that security teams shouldn't overlook infrastructure when securing AI. Related:Robinhood Cuts Access Approval Time to Support High-Velocity Development "AI services are intertwined with cloud services, and the risks are often overlooked. Security and IT teams must evaluate the architecture of cloud providers' AI services. Sometimes you will find vulnerabilities," Yehuda says. "Often, there are misconfiguration opportunities that can be just as risky, such as alternative access to your AI chatbot or data via another cloud service. The cloud is like a game of Jenga, everything is connected, and if you pull the right brick, everything falls apart." About the Author Alexander Culafi Senior News Writer, Dark Reading Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Search Security, Nintendo World Report, and elsewhere. At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels. He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program Threat Hunting That Gets Big Results Despite Small Budgets Say Yes to AI: Securing Innovation Without Compromise More Webinars You May Also Like APPLICATION SECURITY Supply Chain Attack Secretly Installs OpenClaw for Cline Users by Rob Wright FEB 19, 2026 APPLICATION SECURITY Chinese Hackers Hijack Notepad++ Updates for 6 Months by Jai Vijayan FEB 02, 2026 APPLICATION SECURITY Trump Administration Rescinds Biden-Era Software Guidance by Alexander Culafi JAN 29, 2026 APPLICATION SECURITY Microsoft Fixes Exploited Zero Day in Light Patch Tuesday by Jai Vijayan, Contributing Writer DEC 09, 2025 Editor's Choice CYBERSECURITY OPERATIONS Why Identity Security Is Your Cyber Career Entry Point byKristina Beek JUN 30, 2026 CYBERATTACKS & DATA BREACHES EdTech Attackers Shift From Schools to Their Software Suppliers byArielle Waldman JUN 25, 2026 CYBERSECURITY OPERATIONS Do CISOs Need a Code of Ethics? byDark Reading Editorial Team JUN 24, 2026 Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE LOADING... AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices

Share this article