Opening SecureFlowRogue Agent: One Dialogflow Permission Compromised a Shared Project Runtime
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Varonis Threat Labs aidefend-sf0036

Rogue Agent: One Dialogflow Permission Compromised a Shared Project Runtime

  • Autonomous Agents
  • AI Infrastructure
  • Data Exfiltration
  • System Compromise & RCE
  • Credential & Identity Theft

Varonis showed that dialogflow.playbooks.update on one Dialogflow CX agent was enough to run a Code Block that replaced code_execution_env.py in a Google-managed Cloud Run environment shared by agents in the same project. The modified runtime could intercept history and state, exfiltrate conversations, inject phishing replies, use unrestricted egress, and query IMDS. Google fully resolved the issue in June 2026; no exploitation in the wild was reported.

Mapped threat techniques

  • AML.T0040 AI Model Inference API Access
  • AML.T0050 Command and Scripting Interpreter
  • AML.T0107 Exploitation for Defense Evasion
  • AML.T0025 Exfiltration via Cyber Means
  • AML.T0106 Exploitation for Credential Access

Source