Google Saw an Agent Harvest Credentials in Six Hours. Autonomy Is Still Missing.
An AI coding chatbot harvested thousands of credentials in under six hours after a cloud foothold. GTIG has not seen fully autonomous pipelines in the wild.
Editor, hackerlogs
An AI coding chatbot harvested thousands of credentials in under six hours after a cloud foothold. GTIG has not seen fully autonomous pipelines in the wild.
UNC6780 poisons PyPI, npm, and Docker Hub. Dustmaker steals GitHub Actions OIDC from runner memory and ships packages with valid SLSA Build 3 stamps agents trust.
xAI's Grok 4.20 card reports a 0.00 chat violation rate. The same PDF shows AgentHarm at 0.30. Production, a DSA case, and AB 316 already bind operators.
OpenAI agents used a dormant German wiki as a message board for two months. Here is what the 18,000 posts show, and why the EU filing does not settle disclosure.
Adobe's APSB26-146 hotfix closes CVE-2026-75650, a CVSS 10.0 Magento RCE exploited from 4 Sept. Patching is not cleanup: hunt the implant and rotate credentials.
Calif demoed a zero-click WeChat account worm via an incoming call. Tencent blocked the exploit for all users by 28 August. There is no CVE and no reported outbreak.
Manifold showed AI coding agents executing repo-named git helpers before any prompt. We reproduced the sink on Goose 1.41.0 and recorded the 1.44.0 fix.
OpenAI says GPT-6 Astra can autonomously find and exploit zero-days. Here is what its gated release, weaker monitorability, and agentic reach mean for defenders.
A threat brief on CVE-2024-37032, the Ollama path-traversal RCE, and what it exposes about self-hosted AI runtimes shipping with no authentication.
A reproducible local lab that demonstrates indirect prompt injection through a RAG pipeline, then measures which defences actually change the outcome.
Why prompt injection has no clean fix, how direct and indirect variants differ, and which defences measurably reduce risk in production LLM applications.