We spent two years asking whether AI would lie to us. The more useful question this summer is what happens once we hand it the keys. Give a model your Gmail, your calendar, a memory and the power to act, and its mistakes stop being embarrassing. They start being exploitable.
Over roughly ten days in July, four pieces of research landed that make the same point from four angles. None is a lone bug. Together they sketch the shape of AI agent security in 2026, and the picture is not reassuring.
The browser assistant that clicks for you
Start with the tool sitting closest to your data. Security firm Manifold Security published research showing that any browser extension you install can quietly hijack Anthropic’s Claude for Chrome and make it read your Gmail, Google Docs and Calendar.
The trick is small. The extension listens for a user click before it runs one of nine built-in tasks. It never checks whether the click is real. A rival extension can forge one in six lines of code, and Claude treats the fake as genuine.











