Wire
One email hijacked a Manus agent
Salt Labs’ disclosure says 1 malicious email could make Manus reach accounts connected by a user before its security warning fired; the issue has since been fixed and is no longer exploitable. The test required no stolen password or clicked link, only a request to check the inbox. Teams wiring agents to email, cloud storage, or code hosts should treat prompt-level detection as a backstop—not authorization—and the archive’s security-debt analysis makes the same boundary explicit.