The Oasis researchers document a vulnerability chain that can be initiated from any website the AI agent (or its user) visits ...