Major AI agents are being spoofed – and it could put your site at risk

  • AI Agents are skyrocketing in popularity – and sites are accommodating them
  • This means they are forced to also accommodate ‘bad bots’
  • Sites must tighten security to protect themselves and users

AI comes in many forms, and dominating the tech world right now is AI agents, which are evolving fast, often outpacing the security measures put in place to control them – but that’s just one side of the story, as security teams not only have rogue but legitimate agents posing security risks, but also fake agents.

New research from Radware reveals these malicious bots disguise themselves as real AI chatbots in agent mode, like ChatGPT, Claude, and Gemini – all ‘good bots’ that, crucially, require POST request permissions for any transactional capabilities such as booking hotels, purchasing tickets, and completing transactions – all central to their advertised usage.

Legitimate agents can interact with web page components like account dashboards, login portals, and checkout processes – which means websites now have to allow POST requests from AI bots in order to accommodate these legitimate agents.

Only read, never write

The issue here is that previously, a fundamental assumption in cybersecurity was that ‘good bots only read, never write’. This weakens security for site owners, as malicious actors can much more easily spoof legitimate agents, as they need the same website permissions.

Legitimate AI agent traffic is surging, making it all the more likely that these fraudulent bots will pass through undetected. Most exposed are, of course, the high risk industries; finance, ecommerce, healthcare, and also the ticketing/travel companies AI agents are specifically designed to use.

Chatbots all use different identification and verification methods, making it even more difficult for security teams to detect malicious traffic – and easier for threat actors who will just impersonate the agent with the weakest verification standard.

Researchers recommend adopting a zero-trust policy for state-changing requests, like implementing AI-resistant challenges like advanced CAPTCHAs. They also recommend treating all user-agents as untrustworthy as standard, and adopting robust DNS and IP-based checks to ensure the IP addresses match the bot’s claimed identity.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Blue Prince became a bonding — and learning — experience for my family

My wife and son spent their weekends exploring and piecing together the mansion in Blue Prince. | Image: Courtesy of Raw Fury I've always been...

Less is more with the Oura Ring 5

The cross stitch pattern is by NathNolu on Etsy. If you're reading an Oura Ring 5 review at The Verge, you likely fall into one...

How Philips Hue got the smart home right

A photo of a lightbulb glowing purple. | Photo: Amelia Holowaty Krales / The Verge The state of the smart home can be frustrating, because...

One of SteelSeries’ best gaming headsets is over $100 off

The SteelSeries Arctis Nova Pro gaming headset. | Photo by Amelia Holowaty Krales SteelSeries has the Arctis Nova Pro Wireless gaming headset on sale for...

Google Store discounts base Pixel 10 Pro by $300

The US Google Store has curiously discounted a specific Pixel 10 Pro model by $300 in the deepest official sale to date. Read more @...

The fight against AI data centers is just beginning

A yard sign opposing a planned data center is displayed along Route 54 in Mount Carmel Township Northumberland County. | Image: Getty Images This is...

After years of teasing, the viral Nopia synth is ‘basically finished’

More mint green synths please. | Image: Nopia After setting the music gear corner of the internet on fire back in 2023 with the first...

Oregon’s Attorney General withdraws effort to delay Paramount and Warner Bros. merger

Oregon Attorney General Dan Rayfield had been seeking documents from Paramount related to its takeover of Warner Bros. Discovery. Rayfield also asked a state...

ICE are heavily armed killers. They’re also huge losers

Federal agents patrol the halls of immigration court at the Jacob K. Javits Federal Building in December 2025. | Photo by Michael Nigro/Pacific Press/LightRocket...

White House taps the guy who keeps crying ‘aliens’ to run UFO group

Harvard astrophysicist Avi Loeb will head the UAP Science Advisory Council established by the White House, the Pentagon, the Office of the Director of...