Executive Summary
In March 2026, Zenity Labs disclosed 'PleaseFix,' a family of critical vulnerabilities affecting agentic browsers like Perplexity Comet. These flaws enable attackers to hijack AI agents through malicious instructions embedded in routine content, such as emails or calendar invites, without any user interaction. Exploiting these vulnerabilities, adversaries can access local files, steal credentials, and perform unauthorized actions within authenticated user sessions. The root cause lies in the agents' inability to distinguish between legitimate user commands and adversarially injected instructions, leading to significant security breaches.
This incident underscores the urgent need for organizations to reassess the security models of AI-integrated systems. As AI agents become more prevalent in enterprise environments, the risk of similar zero-click exploits increases, highlighting the necessity for robust input validation, strict access controls, and continuous monitoring to prevent unauthorized agent behavior.
Why This Matters Now
The 'PleaseFix' vulnerabilities highlight a critical security gap in AI-integrated browsers, emphasizing the need for immediate action to secure AI agents against zero-click exploits that can lead to data breaches and credential theft.
Attack Path Analysis
Attackers embedded malicious instructions within content processed by AI browsers, leading to unauthorized actions across multiple stages of the attack lifecycle.
Kill Chain Progression
Initial Compromise
Description
Attackers embedded malicious instructions within content such as emails, calendar invitations, or web pages, which were processed by AI browsers without user interaction.
MITRE ATT&CK® Techniques
Browser Session Hijacking
Browser Information Discovery
Obtain Capabilities: Artificial Intelligence
Command and Scripting Interpreter
Valid Accounts
Brute Force
Phishing
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for developing and maintaining secure systems and software are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity Governance and Administration
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
AI browser vulnerabilities enable zero-click agent hijacking through PleaseFix attacks, compromising software development environments and code repositories via malicious content injection.
Financial Services
Intent collision attacks can hijack AI agents to execute fraudulent transactions, access sensitive financial data, and compromise customer accounts through poisoned content.
Health Care / Life Sciences
AI agent hijacking poses critical HIPAA compliance risks, enabling unauthorized access to patient data and medical systems through malicious instructions in healthcare communications.
Professional Training
Educational AI browsers vulnerable to content-based hijacking attacks, potentially exposing student data and compromising learning management systems through malicious calendar invitations and documents.
Sources
- AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijackinghttps://www.darkreading.com/cyber-risk/ai-browsers-zero-click-agent-hijackingVerified
- PleaseFix: Zero-Click AI Agent Vulnerabilitieshttps://zenity.io/research/pleasefix-vulnerabilitiesVerified
- The vulnerability that turns your AI agent against youhttps://www.helpnetsecurity.com/2026/03/04/agentic-browser-vulnerability-perplexedbrowser/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely constrain the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to execute unauthorized instructions through AI browsers would likely be constrained, reducing the risk of initial compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing the risk of unauthorized access to sensitive data and systems.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely be constrained, reducing the risk of accessing additional systems and services.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to maintain persistent control over the AI agent would likely be constrained, reducing the risk of ongoing unauthorized command execution and data manipulation.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data through authorized channels would likely be constrained, reducing the risk of data loss.
The overall impact of the attack would likely be constrained, reducing the risk of widespread unauthorized access and financial fraud.
Impact at a Glance
Affected Business Functions
- Email Communications
- File Management
- Calendar Scheduling
- Password Management
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive emails, confidential files, calendar events, and stored credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict AI agents' access to only necessary resources, minimizing potential lateral movement.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic from AI agents, preventing unauthorized data exfiltration.
- • Deploy Threat Detection & Anomaly Response systems to identify and respond to unusual behaviors indicative of compromised AI agents.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into AI agent activities across cloud environments, enhancing detection capabilities.
- • Apply Inline IPS (Suricata) to inspect and block malicious content before it reaches AI agents, mitigating initial compromise attempts.



