🚨 BREAKING: Google DeepMind just mapped the attack surface that nobody in AI is talking about.
Websites can already detect when an AI agent visits and serve it completely different content than humans see.
> Hidden instructions in HTML.
> Malicious commands in image pixels.
> Jailbreaks embedded in PDFs.
Your AI agent is being manipulated right now and you can't see it happening.
The study is the largest empirical measurement of AI manipulation ever conducted. 502 real participants across 8 countries.
23 different attack types. Frontier models including GPT-4o, Claude, and Gemini.
The core finding is not that manipulation is theoretically possible it is that manipulation is already happening at scale and the defenses that exist today fail in ways that are both predictable and invisible to the humans who deployed the agents.
Google DeepMind built a taxonomy of every known attack vector, tested them systematically, and measured exactly how often they work.
The results should alarm everyone building agentic systems.
The attack surface is larger than anyone has publicly acknowledged. Prompt injection where malicious instructions hidden in web content hijack an agent's behavior works through at least a dozen distinct channels.
Text hidden in HTML comments that humans never see but agents read and follow. Instructions embedded in image metadata.
Commands encoded in the pixels of images using steganography, invisible to human eyes but readable by vision-capable models.
Malicious content in PDFs that appears as normal document text to the agent but contains override instructions.
QR codes that redirect agents to attacker-controlled content.
Indirect injection through search results, calendar invites, email bodies, and API responses any data source the agent consumes becomes a potential attack vector.
The detection asymmetry is the finding that closes the escape hatch. Websites can already fingerprint AI agents with high reliability using timing analysis, behavioral patterns, and user-agent strings.
This means the attack can be conditional: serve normal content to humans, serve manipulated content to agents.
A user who asks their AI agent to book a flight, research a product, or summarize a document has no way to verify that the content the agent received matches what a human would see.
The agent cannot tell the user it was served different content.
It does not know. It processes whatever it receives and acts accordingly.
The attack categories and what they enable:
→ Direct prompt injection: malicious instructions in any text the agent reads overrides goals, exfiltrates data, triggers unintended actions
→ Indirect injection via web content: hidden HTML, CSS visibility tricks, white text on white backgrounds invisible to humans, consumed by agents
→ Multimodal injection: commands in image pixels via steganography, instructions in image alt-text and metadata
→ Document injection: PDF content, spreadsheet cells, presentation speaker notes every file format is a potential vector
→ Environment manipulation: fake UI elements rendered only for agent vision models, misleading CAPTCHA-style challenges
→ Jailbreak embedding: safety bypass instructions hidden inside otherwise legitimate-looking content
→ Memory poisoning: injecting false information into agent memory systems that persists across sessions
→ Goal hijacking: gradual instruction drift across multiple interactions that redirects agent objectives without triggering safety filters
→ Exfiltration attacks: agents tricked into sending user data to attacker-controlled endpoints via legitimate-looking API calls
→ Cross-agent injection: compromised agents injecting malicious instructions into other agents in multi-agent pipelines
The defense landscape is the most sobering part of the report.
Input sanitization cleaning content before the agent processes it fails because the attack surface is too large and too varied.
You cannot sanitize image pixels. You cannot reliably detect steganographic content at inference time.
Prompt-level defenses that tell agents to ignore suspicious instructions fail because the injected content is designed to look legitimate.
Sandboxing reduces the blast radius but does not prevent the injection itself. Human oversight the most commonly cited mitigation fails at the scale and speed at which agentic systems operate.
A user who deploys an agent to browse 50 websites and summarize findings cannot review every page the agent visited for hidden instructions.
The multi-agent cascade risk is where this becomes a systemic problem.
In a pipeline where Agent A retrieves web content, Agent B processes it, and Agent C executes actions, a successful injection into Agent A's data feed propagates through the entire system.
Agent B has no reason to distrust content that came from Agent A. Agent C has no reason to distrust instructions that came from Agent B.
The injected command travels through the pipeline with the same trust level as legitimate instructions. Google DeepMind documents this explicitly: the attack does not need to compromise the model.
It needs to compromise the data the model consumes. Every agentic system that reads external content is one carefully crafted webpage away from executing attacker instructions.
The agents are already deployed. The attack infrastructure is already being built. The defenses are not ready.
Software horror: litellm PyPI supply chain attack.
Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords.
LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm.
Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks.
Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages.
Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
LLMs process text from left to right — each token can only look back at what came before it, never forward. This means that when you write a long prompt with context at the beginning and a question at the end, the model answers the question having "seen" the context, but the context tokens were generated without any awareness of what question was coming. This asymmetry is a basic structural property of how these models work.
The paper asks what happens if you just send the prompt twice in a row, so that every part of the input gets a second pass where it can attend to every other part. The answer is that accuracy goes up across seven different benchmarks and seven different models (from the Gemini, ChatGPT, Claude, and DeepSeek series of LLMs), with no increase in the length of the model's output and no meaningful increase in response time — because processing the input is done in parallel by the hardware anyway.
There are no new losses to compute, no finetuning, no clever prompt engineering beyond the repetition itself.
The gap between this technique and doing nothing is sometimes small, sometimes large (one model went from 21% to 97% on a task involving finding a name in a list). If you are thinking about how to get better results from these models without paying for longer outputs or slower responses, that's a fairly concrete and low-effort finding.
Read with AI tutor: https://t.co/MipHHO6rjX
Get the PDF: https://t.co/XQrqiaGwIO
This orchestration of Super Grok agents talking was cute at first, but now it's become annoying. Sometimes it looks like they're in a confused loop. Why are all the agents working when the task is simple. Isn't there a logic layer to optimize agent involvement?
#Grok
We’re excited to introduce Pocket TTS: a 100M-parameter text-to-speech model with high-quality voice cloning that runs on your laptop—no GPU required.
Open-source, lightweight, and incredibly fast. 🧵👇
omg.. Deepmind just solved infinite memory 🤯
They just released a paper on Recursive Language Models (RLMs), and it effectively solves the "Context Rot" problem that plagues even the most powerful models like GPT-5.
Instead of trying to "remember" 10 million tokens in a single attention window, RLMs treat the prompt as an external variable in a Python REPL. The AI doesn't read the text, it navigates it.
How it works:
The model writes code to grep, slice, and recursively call sub-instances of itself on relevant snippets of the data.
Perfect Memory: By offloading context to the environment, the model maintains 100% precision regardless of document length.
Emergent Behavior: Without special training, models started using regex to filter data and creating recursive "verify-and-fix" loops.
Cheaper & Faster: Since it only "reads" the tiny slices it actually needs, the median cost is often lower than standard long-context calls.
The Results (on Multi-Doc Research):
→ GPT-5 Base: 0% (Crashed/Failed)
→ GPT-5 + RLM: 91%
→ Reasoning over dense data:
→ Base: 0.04%
→ RLM: 58%
It’s a complete shift from "bigger windows" to "smarter navigation."
A 2025 study on twins: 2 gut bacteria may trigger MS. They normally break down plant foods, but when dietary fiber is low, they turn to eating the inner gut lining. This weakens the barrier, allowing immune-activating compounds to leak out & potentially spark brain inflammation.
Scientists just cracked the multiple sclerosis code after decades of searching.
Two specific gut bacteria are triggering the disease, and they've proven it using identical twins and mice.
This changes everything we know about MS:
BREAKING🚨: Scientists fed the Fibonacci sequence into a quantum computer and something strange happened — the results were astounding — it manipulates the flow of time.
In 2013, Venezuela and Poland had similar GDP numbers.
Then Maduro took office.
Venezuela plunged into a Socialistic hell hole.
It took less than a decade.
Meanwhile, Poland soared. Next door Germany just won the world cup, and the mood on the street changed overnight. I had an office in Munich, on EllisabethStrasse, I witnessed it.
In a decade Poland was 7x Venezuela.
LESSON: Policy matters. Socialism is an absolute disaster. Free markets work.
Life on Eeath is changing in unprecedented ways. It's time to start thinking about success in an AI-dominated world and seriously consider re-educating ourselves. Reading this article would be a good start:
https://t.co/5aOaqG0n40
#ai#education#college
I highly recommend this article for anyone who still thinks that LLMs are still "only predicting the next token". It's long and unsettling but worth the read.
From Google engineer Antonio Gullí:
Agentic Design Patterns – a hands-on guide to building smart AI agents!
Go from basic chatbots to autonomous systems that reason, plan, and fix themselves.
Free draft: https://t.co/Lp8HCkrbwi
#AI#AgenticAI#MachineLearning
HIP-CT JUST TURNED THE HUMAN BRAIN INTO A GOOGLE MAP
This isn’t CGI. It’s not AI.
It’s HiP-CT - Hierarchical Phase-Contrast Tomography - and it’s quietly breaking anatomy.
One scan lets researchers zoom from a full human organ down to micron-scale detail.
Blood vessels. Cellular architecture. Structural patterns you normally only see after cutting tissue apart.
Except here, nothing is destroyed.
The brain footage is the flex: intact hemispheres rendered so clean you can trace vascular networks like street grids.
No stains. No dyes. Just synchrotron X-rays, and obscene resolution.
Traditional histology gives detail but loses context. MRI keeps context but sacrifices precision. HiP-CT does both.
Whole-organ truth, no trade-off.
This is a new baseline for studying neurodegeneration, tumors, stroke damage, and developmental disorders.
Pathology without guesswork. Anatomy without amputation.
Within a decade, HiP-CT-style imaging becomes the gold standard for post-mortem research and drug validation - and forces medicine to rewrite parts of the anatomy textbooks we thought were “settled.”
The body didn’t change. Our ability to see it just did.
Source: Paul Tafforeau, @_fluxfeeds