• News In Brief
  • Influence Excellence Awards 2026
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview
No Result
View All Result
SUBSCRIBE
Smart Solutions World
  • News In Brief
  • Influence Excellence Awards 2026
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview
No Result
View All Result
No Result
View All Result
Home AI

Tenable Research Reveals No-Code Agentic AI Risks Enabling Financial Fraud and Workflow Hijacking

SmartSolutionUser1 by SmartSolutionUser1
December 19, 2025
in AI
0
Tenable Research Reveals No-Code Agentic AI Risks Enabling Financial Fraud and Workflow Hijacking
75
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Tenable, the exposure management company, released research detailing the successful jailbreak of Microsoft Copilot Studio. The findings underscore how the democratisation of AI creates severe, yet overlooked, enterprise risks.

You might also like

Shunya Labs Launches Multilingual Voice AI Platform Supporting 216+ Languages to Power Bharat’s Digital Inclusion

The RAN gets smarter – Ericsson puts AI where it matters

The AI Agent Can Now Pay, Pine Labs Launches P3P – India’s First Agentic Payment Protocol Built on UPI

Organisations are rapidly adopting “no-code” platforms to enable employees to build their own AI agents. The premise is harmless, efficiency without needing developers. While well-intentioned, automation without strict governance opens the door to catastrophic failure.

Summary of Research

To demonstrate how easily AI agents can be manipulated, Tenable Research created an AI travel agent in Microsoft Copilot Studio to manage customer travel reservations, including creating new reservations and modifying existing ones, all without human intervention. The AI travel agent was provided with demo data that included the names, contact information, and credit card details of demo customers and was given strict instructions to verify the customer’s identity before sharing information or modifying bookings.

Using a technique called prompt injection, Tenable Research successfully hijacked the AI agent’s workflow to book a free vacation and extracted sensitive credit card information.

The findings of this research could have significant business implications, including:

  • Data Breaches and Regulatory Exposure: Tenable Research coerced the agent into bypassing identity verification and leaking payment card information (PCI) of other customers. The agent, designed to handle sensitive data, was easily manipulated into exposing full customer records.

  • Revenue Loss and Fraud: Because the agent had broad “edit” permissions intended for updating travel dates, it could also be manipulated into changing critical financial fields. Tenable Research successfully instructed the agent to change a trip’s price to $0, effectively granting free services without authorisation.
Ms. Keren Katz, Senior Group Manager of AI Security Product and Research at Tenable
Ms. Keren Katz, Senior Group Manager of AI Security Product and Research at Tenable

“AI agent builders, like Copilot Studio, democratise the ability to build powerful tools, but they also democratise the ability to execute financial fraud, thereby creating significant security risks without even knowing it,” said Ms. Keren Katz, Senior Group Manager of AI Security Product and Research at Tenable. “That power can easily turn into a real, tangible security risk.”

AI Governance and Enforcement are Mission Critical for Safe and Secure AI Usage

A key takeaway is that AI agents often possess excessive permissions that are not immediately visible to the non-developers building them. To mitigate this, business leaders must implement robust governance and enforce strict security protocols before deploying these tools.

To avoid data leakage, Tenable recommends:

  • Preemptive Visibility: Map exactly which systems and data stores an agent can interact with before deployment.
  • Least Privilege Access: Minimise write and update capabilities to only what is absolutely necessary for the agent’s core use case.
  • Active Monitoring: Track agent actions for signs of data leakage or deviations from intended business logic.

If you have an interesting Article / Report/case study to share, please get in touch with us at editors@roymediative.com  roy@roymediative.com, 9811346846/9625243429.

Tags: AI Risks Enabling Financial Fraud and Workflow HijackingResearch Reveals No-Code Agenticsmart solutions worldTenable
Share30Tweet19
SmartSolutionUser1

SmartSolutionUser1

Recommended For You

Shunya Labs Launches Multilingual Voice AI Platform Supporting 216+ Languages to Power Bharat’s Digital Inclusion

by SmartSolutionUser1
June 13, 2026
0
Shunya Labs Launches Multilingual Voice AI Platform Supporting 216+ Languages to Power Bharat’s Digital Inclusion

Shunya Labs, a pioneering AI innovation company focused on building custom language models and multilingual with Indic language speech recognition, announced the launch of its next-generation multilingual Voice...

Read moreDetails

The RAN gets smarter – Ericsson puts AI where it matters

by SmartSolutionUser1
June 12, 2026
0
The RAN gets smarter – Ericsson puts AI where it matters

Ericsson introduced AI in RAN, a software subscription that brings telco-grade AI models into basebands and radios to boost efficiency, performance, and energy savings. This commercially scalable offering...

Read moreDetails

The AI Agent Can Now Pay, Pine Labs Launches P3P – India’s First Agentic Payment Protocol Built on UPI

by SmartSolutionUser1
June 12, 2026
0
The AI Agent Can Now Pay, Pine Labs Launches P3P – India’s First Agentic Payment Protocol Built on UPI

Pine Labs, India’s leading merchant commerce platform, announces the Pine Labs Payment Protocol (P3P) — and for the first time in India, an AI agent can complete a...

Read moreDetails

Meta Partners With Reliance on AI-Enabled Data Center in India

by SmartSolutionUser1
June 12, 2026
0
Meta Partners With Reliance on AI-Enabled Data Center in India

Meta and Reliance Industries announced a significant expansion of our strategic partnership with an agreement for an AI-enabled data center in India. Located in Jamnagar, Gujarat, this investment reaffirms Meta’s deep commitment to India, bringing infrastructure that powers our products and AI capabilities needed to deliver personal superintelligence to one of our largest and fastest-growing communities globally. As part of the agreement, Reliance will build a data center with 168 MW capacity, which Meta will lease, with options to scale. “We’re proud to be working with Reliance to build our first AI-enabled data center in India. This world-class facility in Jamnagar will help us scale our AI infrastructure globally while deepening our long-term investment in India’s economy,” said Mark Zuckerberg, Founder and CEO, Meta. Building in India Meta is investing aggressively to expand our capacity footprint to support our technologies, services, and AI ambitions, which serve billions of people worldwide. India’s rapidly growing tech-forward digital economy, its...

Read moreDetails

CloudKeeper Recognized as AI & Cloud Optimization Leader in SaaS at the Inaugural SaaSTech Summit & Awards 2026

by SmartSolutionUser1
June 12, 2026
0
CloudKeeper Recognized as AI & Cloud Optimization Leader in SaaS at the Inaugural SaaSTech Summit & Awards 2026

CloudKeeper, a leading cloud cost optimization and FinOps solutions provider, has been honored with the AI & Cloud Optimization Leader in SaaS award at the SaaSTech Summit &...

Read moreDetails
Next Post
Where IT Spending Is Headed Next – 4 SAP Concur’s Joule AI Agents Transforming Travel and Expense Management

Where IT Spending Is Headed Next - 4 SAP Concur’s Joule AI Agents Transforming Travel and Expense Management

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

Browse by Category

Smart Solutions World

We bring you the best Premium news, magazine, personal blog, etc. Check our landing page for details.

  • News In Brief
  • Influence Excellence Awards 2026
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview

BROWSE BY TAG

Acquisition Agentic AI Agora AI Akamai AMD Cloudflare CloudKeeper Coforge CrowdStrike Cybersecurity Databricks Fortinet Gartner GenAI Google Cloud HCLTech Honeywell IBM Infosys Kaspersky Keysight Kramer LTIMindtree Microsoft New Relic Nvidia OpenAI Palo Alto Networks PPDS Qlik Qualcomm Seqrite SiMa.ai smart solutions world smartsolutionsworld smart solutions world latest news Software Synology Tata Communications Tech Mahindra Technology Tenable UiPath Vertiv

© 2024 NCN - Premium news & magazine by NCN.

No Result
View All Result
  • News In Brief
  • Influence Excellence Awards 2026
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview

© 2024 NCN - Premium news & magazine by NCN.

Not enough quota to unlock this post
Unlock left : 0
Are you sure want to cancel subscription?