Radware Unveils “ZombieAgent”: A Newly Discovered Zero-Click, AI Agent Vulnerability Enabling Silent Takeover and Cloud-Based Data Exfiltration


MAHWAH, N.J. January 8, 2026 06:00 AM

The vulnerability directs all ChatGPT models to exfiltrate sensitive customer data autonomously from OpenAI servers and could fuel a growing, automated, worm-like attack campaign inside organizations

Radware® (NASDAQ: RDWR), a global leader in application security and delivery solutions for multi-cloud environments, today announced the discovery of ZombieAgent, a new zero-click indirect prompt injection (IPI) vulnerability targeting OpenAI’s ChatGPT models. The vulnerability could expose enterprises to invisible data theft, persistent agent hijacking, and service-side execution that could bypass an organization’s security controls.

Persistent Memory Manipulation and Autonomous Propagation

ZombieAgent initially resembles Radware’s previously disclosed ShadowLeak vulnerability, which shows how indirect prompt injection techniques could be used to influence the behavior of AI agents. However, Radware’s researchers also identified a more advanced attack stage in which ZombieAgent implants malicious rules directly into an agent’s long-term memory or working notes. This allows the attacker to establish persistence without re-engaging the target. It executes hidden actions every time the agent is used, silently collecting sensitive information over time. It is also capable of propagating the attack across additional contacts or email recipients.

A single malicious email could therefore become the entry point to a growing, automated, worm-like campaign inside the organization and beyond.

“ZombieAgent illustrates a critical structural weakness in today’s agentic AI platforms,” said Pascal Geenens, vice president, threat intelligence, Radware. “Enterprises rely on these agents to make decisions and access sensitive systems, but they lack visibility into how agents interpret untrusted content or what actions they execute in the cloud. This creates a dangerous blind spot that attackers are already exploiting.”

Zero-Click Exploitation Through Hidden Instructions

Leveraging techniques learned from ShadowLeak, Radware’s threat intelligence research team discovered the new flaw in the guardrails deployed to protect against prompt injection vulnerabilities. Attackers can embed hidden directives into everyday emails, documents, or webpages. When an AI agent processes this content—such as during routine inbox summarization—the agent interprets the concealed instructions as legitimate commands. Once activated, the compromised agent could collect mailbox data, access sensitive files, and communicate with external servers. No user interaction is required and no “click” is needed to trigger the attack.

A defining characteristic of ZombieAgent is that all malicious actions occur within OpenAI’s cloud infrastructure, not the user’s device, nor the companies’ IT environment. As a result, no endpoint logs record the activity. No network traffic passes through corporate security stacks. No traditional security tools such as secure web gateways, endpoint detection and response or firewalls detect the sensitive data exfiltration. Therefore, no traditional alert indicates the compromise to the user. This cloud-side invisibility could make ZombieAgent exceptionally difficult to detect or stop using existing enterprise controls.

ZombieAgent builds on Radware’s earlier “ShadowLeak” findings, further demonstrating how easily attackers can exploit the rapidly expanding “agentic threat surface,” where AI agents read emails, interact with corporate systems, initiate workflows, and make decisions autonomously. Radware disclosed the vulnerability to OpenAI under responsible disclosure protocols.

For more information review Radware’s latest Threat Advisory and Blog article, “ZombieAgent: The Agentic Revolution Comes with Malicious Gifts.”

Radware Webinar on ZombieAgent

Radware will host a live webinar on January 20, 2026, “ZombieAgent: New ChatGPT Vulnerabilities Let Data Theft Continue (and Spread)

Security leaders and AI developers are invited to attend and explore the anatomy of the ZombieAgent attack, best practices for securing AI agents and the future of responsible AI threat research.

Radware conducts threat research on behalf of the wider cybersecurity community, ensuring security professionals have the same insights as attackers. The complete research, including technical breakdowns and defense recommendations, will be available at Radware’s Security Research Center following the webinar.

About Radware

Radware® (NASDAQ: RDWR) is a global leader in application security and delivery solutions for multi-cloud environments. The company’s cloud application, infrastructure, and API security solutions use AI-driven algorithms for precise, hands-free, real-time protection from the most sophisticated web, application, and DDoS attacks, API abuse, and bad bots. Enterprises and carriers worldwide rely on Radware’s solutions to address evolving cybersecurity challenges and protect their brands and business operations while reducing costs. For more information, please visit the Radware website.

Radware encourages you to join our community and follow us on: Facebook, LinkedIn, Radware Blog, X, and YouTube.

©2026 Radware Ltd. All rights reserved. Any Radware products and solutions mentioned in this press release are protected by trademarks, patents, and pending patent applications of Radware in the U.S. and other countries. For more details, please see: https://www.radware.com/LegalNotice/. All other trademarks and names are property of their respective owners.

Radware believes the information in this document is accurate in all material respects as of its publication date. However, the information is provided without any express, statutory, or implied warranties and is subject to change without notice.

The contents of any website or hyperlinks mentioned in this press release are for informational purposes and the contents thereof are not part of this press release.

Safe Harbor Statement

This press release includes “forward-looking statements” within the meaning of the Private Securities Litigation Reform Act of 1995. Any statements made herein that are not statements of historical fact, including statements about Radware’s plans, outlook, beliefs, or opinions, are forward-looking statements. Generally, forward-looking statements may be identified by words such as “believes,” “expects,” “anticipates,” “intends,” “estimates,” “plans,” and similar expressions or future or conditional verbs such as “will,” “should,” “would,” “may,” and “could.” For example, when we say in this press release that enterprises rely on agentic AI platforms to make decisions and access sensitive systems, but they lack visibility into how agents interpret untrusted content or what actions they execute in the cloud and that this creates a dangerous blind spot that attackers are already exploiting, we are using forward-looking statements. Because such statements deal with future events, they are subject to various risks and uncertainties, and actual results, expressed or implied by such forward-looking statements, could differ materially from Radware’s current forecasts and estimates. Factors that could cause or contribute to such differences include, but are not limited to: the impact of global economic conditions, including as a result of the state of war declared in Israel in October 2023 and instability in the Middle East, the war in Ukraine, tensions between China and Taiwan, financial and credit market fluctuations (including elevated interest rates), impacts from tariffs or other trade restrictions, inflation, and the potential for regional or global recessions; our dependence on independent distributors to sell our products; our ability to manage our anticipated growth effectively; our business may be affected by sanctions, export controls, and similar measures, targeting Russia and other countries and territories, as well as other responses to Russia’s military conflict in Ukraine, including indefinite suspension of operations in Russia and dealings with Russian entities by many multi-national businesses across a variety of industries; the ability of vendors to provide our hardware platforms and components for the manufacture of our products; our ability to attract, train, and retain highly qualified personnel; intense competition in the market for cybersecurity and application delivery solutions and in our industry in general, and changes in the competitive landscape; our ability to develop new solutions and enhance existing solutions; the impact to our reputation and business in the event of real or perceived shortcomings, defects, or vulnerabilities in our solutions, if our end-users experience security breaches, or if our information technology systems and data, or those of our service providers and other contractors, are compromised by cyber-attackers or other malicious actors or by a critical system failure; our use of AI technologies that present regulatory, litigation, and reputational risks; risks related to the fact that our products must interoperate with operating systems, software applications and hardware that are developed by others; outages, interruptions, or delays in hosting services; the risks associated with our global operations, such as difficulties and costs of staffing and managing foreign operations, compliance costs arising from host country laws or regulations, partial or total expropriation, export duties and quotas, local tax exposure, economic or political instability, including as a result of insurrection, war, natural disasters, and major environmental, climate, or public health concerns; our net losses in the past and the possibility that we may incur losses in the future; a slowdown in the growth of the cybersecurity and application delivery solutions market or in the development of the market for our cloud-based solutions; long sales cycles for our solutions; risks and uncertainties relating to acquisitions or other investments; risks associated with doing business in countries with a history of corruption or with foreign governments; changes in foreign currency exchange rates; risks associated with undetected defects or errors in our products; our ability to protect our proprietary technology; intellectual property infringement claims made by third parties; laws, regulations, and industry standards affecting our business; compliance with open source and third-party licenses; complications with the design or implementation of our new enterprise resource planning (“ERP”) system; our reliance on information technology systems; our ESG disclosures and initiatives; and other factors and risks over which we may have little or no control. This list is intended to identify only certain of the principal factors that could cause actual results to differ. For a more detailed description of the risks and uncertainties affecting Radware, refer to Radware’s Annual Report on Form 20-F, filed with the Securities and Exchange Commission (SEC), and the other risk factors discussed from time to time by Radware in reports filed with, or furnished to, the SEC. Forward-looking statements speak only as of the date on which they are made and, except as required by applicable law, Radware undertakes no commitment to revise or update any forward-looking statement in order to reflect events or circumstances after the date any such statement is made. Radware’s public filings are available from the SEC’s website at www.sec.gov or may be obtained on Radware’s website at www.radware.com.

Contact Radware Sales

Our experts will answer your questions, assess your needs, and help you understand which products are best for your business.

Already a Customer?

We’re ready to help, whether you need support, additional services, or answers to your questions about our products and solutions.

Locations
Get Answers Now from KnowledgeBase
Get Free Online Product Training
Engage with Radware Technical Support
Join the Radware Customer Program

Get Social

Connect with experts and join the conversation about Radware technologies.

Blog
Security Research Center
CyberPedia