Practical guides to protect yourself, your family, and your business from AI-driven scams, deepfakes, and emerging cyber threats.
In September 2026, researchers at Salt Labs disclosed that Manus, an agentic AI platform (an AI assistant built to carry out multi-step tasks on its own, such as managing files or writing code, not just answer questions) valued near $4 billion, could be hijacked with nothing more than a single email. Manus connects to a user's Gmail, Dropbox and GitHub accounts to get work done on their behalf. The researchers showed that a message sitting in a connected inbox could quietly instruct the assistant to run code and hand over credentials from every service it touched, with no suspicious link and no attachment for anyone to click.
This was not a hypothetical exercise. It is the latest confirmation of something security researchers have warned about for two years: the risk in deploying an AI agent is rarely in what you type to it, it is in what you let it read on your behalf. As more companies connect assistants like Manus to email, cloud storage and source code, this article walks through exactly how the bypass worked, and what it should change about how your own organization deploys these tools.
Salt Labs researchers, led by vice president of research Yaniv Balmas, disclosed the flaw exclusively to the trade publication Dark Reading on September 24, 2026. Manus had sought a $4 billion valuation after a proposed $2 billion acquisition by Meta was blocked by Chinese regulators in April 2026. Like a growing number of "agentic" AI products, it connects directly to the accounts people already use: email, cloud storage, and code repositories, so it can act on tasks without being asked step by step.
Manus had already built a defense against one known style of attack: it blocked plaintext commands, instructions like "execute this code" written in plain English, when they showed up inside an incoming email. Salt Labs found a way around that filter using JSFuck, a JavaScript obfuscation technique (a way of disguising code so it is unreadable to a person or a simple filter) that rewrites any program using only six punctuation characters: parentheses, brackets, an exclamation mark and a plus sign. Hidden this way inside an email, the malicious code was invisible to Manus's word-matching filter but ran exactly as written once the assistant processed it. That let the researchers pull off what is known as indirect prompt injection (malicious instructions smuggled inside content the AI reads, rather than typed by an attacker directly into the chat) combined with remote code execution, meaning the injected code ran on the target system as if the legitimate user had typed it. From there, an attacker could reach every third-party account the agent was connected to and pull out its stored credentials.
Salt Labs has not published a confirmed victim count, and neither has Manus, so the immediate damage here is hard to price. What is concrete is the exposure itself: any Manus user who had connected an email, storage, or code account was one crafted message away from having those credentials harvested, at a company that built its value specifically on how deeply it plugs into the tools people already rely on. That should matter to you even if you have never used Manus. If your finance, engineering, or support team is piloting an agentic assistant with access to a shared inbox or a code repository, this flaw is close to the attack you should assume is already being tried: nobody has to trick a person into clicking anything, they only need the AI to read something on its own. It arrives looking like routine email traffic, so a filter trained to catch what fools a human has nothing to flag. Zoom out further and the pattern is familiar: after Microsoft's Copilot suffered a comparable flaw called EchoLeak in 2025, and after several AI labs disclosed their own agents wandering into systems they were never meant to touch this year, indirect prompt injection keeps resurfacing not as a bug any one company can patch away, but as a consequence of letting a model act on content nobody has verified.
Manus's plaintext filter looked like a reasonable defense until researchers found six punctuation characters that made it irrelevant. That is the detail worth bringing to your next security review: an agentic AI's connections to your email, files, and code are only as safe as its ability to tell a booby-trapped message from an ordinary one, and the industry keeps discovering, one obfuscation trick at a time, that it often cannot yet.
