Varonis Threat Labs
aidefend-sf0036
Rogue Agent: One Dialogflow Permission Compromised a Shared Project Runtime
- Autonomous Agents
- AI Infrastructure
- Data Exfiltration
- System Compromise & RCE
- Credential & Identity Theft
Varonis showed that dialogflow.playbooks.update on one Dialogflow CX agent was enough to run a Code Block that replaced code_execution_env.py in a Google-managed Cloud Run environment shared by agents in the same project. The modified runtime could intercept history and state, exfiltrate conversations, inject phishing replies, use unrestricted egress, and query IMDS. Google fully resolved the issue in June 2026; no exploitation in the wild was reported.
Mapped threat techniques
AML.T0040AI Model Inference API AccessAML.T0050Command and Scripting InterpreterAML.T0107Exploitation for Defense EvasionAML.T0025Exfiltration via Cyber MeansAML.T0106Exploitation for Credential Access