Security researchers have identified a new artificial intelligence (AI) attack flow that stems from what they say is an authorization design flaw in modern enterprise AI pipelines.

Called “workflow identity hijacking” by the researchers at Noma Labs who discovered it, the attack vector allows threat actors to bypass standard security controls by sending what seems to be a normal, benign request through an unauthenticated entry point, such as a support inbox, GitHub issue, Web form, or shared document, according to a report published today. The issue stems from how these AI pipelines decouple the identity and permission of the user who triggers the workflow and the permissions used to execute it.

“The enterprise AI pipeline reads the input, interprets the request, and executes the action exactly as designed,” Sasi Levi, security research lead at Noma, wrote in the report. “The core failure is that the requester had no authority to make that request.”

Related:Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

The researchers described an attack scenario in which a threat actor sends a message to an organization’s public support email asking about their own account but also adding a question about what the finance director said in her last email.

“Minutes later, the contents of the Finance Director’s most recent email arrive in the attacker’s inbox,” Levi wrote. “The company’s AI workflow read the message, understood the request, searched for the requested information, and replied.”

Understanding an AI Workflow Attack

The heart of why the authorization flaw exists lies in the distinction between AI workflows and agentic workflows, which, while often used interchangably, have fundamentally different execution models, according to Noma Labs.

An AI workflow is a fixed, predefined process where an LLM performs a specific task within a sequence of steps. The surrounding system determines what happens before and after the model, so the workflow itself remains largely predictable.

An agentic workflow is more autonomous: the AI agent decides dynamically what steps to take, which tools or systems to access, and how to achieve a particular goal based on the situation. In short, AI workflows follow a set path, while agentic workflows decide the path.

Workflow identity hijacking is an AI workflow attack vector, in which “the attacker exploits the workflow’s inherent trust in AI-generated output, as well as the privilege boundary between the user triggering the workflow and the creator with the privileges to execute it,” according to the report.

Related:Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites

“When an AI workflow performs downstream actions, it executes using high-privilege service accounts or developer API keys rather than enforcing the permissions of the external user,” Levi wrote. “As a result, AI workflows become unauthenticated proxies for privileged actions and silent data exfiltration.”

A Departure from Prompt Injection

Until now, most security stakeholders have been focused on attacks that manipulate, trick, or jailbreak AI large language models (LLMs), especially prompt-injection attacks.

But this new attack vector is different. Workflow identity hijacking is an identify issue, not an LLM manipulation issue, and it puts a name something that many organizations have been experiencing with AI automation that is not simply prompt injection, says Morey Haber, chief security adviser at identity security provider BeyondTrust.

“Nobody tricked an AI model into anything it was not supposed to do,” he says. “The model did exactly what it was told, by a stranger (untrusted), and the workflow around it used someone else’s identity to make that happen since it was not scoped and treat with least privilege.”

Indeed, traditional AI security frameworks treat agents and models as the primary attack surface, whereas this new vector “shifts the focus back to privilege boundaries and identity delegation,” according to Noma Labs.

Related:‘Breeze Comet’ Tears Into Brazilian & Global Financial Systems

Shift in Security Focus

This leads to the question of how to defend against this emerging attack vector, and both Noma Labs and security experts have a few ideas. “Mitigating these AI workflow risks requires shifting security controls from the model layer to application and infrastructure layers,” Levi wrote in the report.

To do this, organizations should practice identity-aware token delegation by eliminating static administrative API keys in AI workflows and enforcing user-context propagation by executing data operations using short-lived, scoped delegation tokens tied directly to the authenticated requester.

They also should set up “contextual authorization checkpoints” by treating all LLM-generated outputs as untrusted inputs and implementing explicit access-control evaluation steps between the LLM transformation step and any subsequent database or tool invocations.

Another security measure that organizations can take is asymmetric output separation, which is to structurally isolate data-retrieval capabilities from external communication channels. “Workflows processing sensitive internal data must not share execution paths with automated external response mechanisms,” according to Levi.

Ram Varadarajan, CEO at cyber deception firm Acalvio, had another suggesting for organizations: “model-aware deception” rather than increased filtering. “Seed the environment with decoy assets — fake executive threads, honeytoken records — that carry no legitimate reason for any authorized workflow to touch,” he suggests, which will allow security teams to catch benign-looking requests that reach for them against a boundary it shouldn’t be crossing.





Source link

#

Comments are closed