Google Saw an Agent Harvest Credentials in Six Hours. Autonomy Is Still Missing.
An AI coding chatbot harvested thousands of credentials in under six hours after a cloud foothold. GTIG has not seen fully autonomous pipelines in the wild.
Tool abuse, excessive agency, confused-deputy attacks, and securing Model Context Protocol servers and agent runtimes.
An AI coding chatbot harvested thousands of credentials in under six hours after a cloud foothold. GTIG has not seen fully autonomous pipelines in the wild.
UNC6780 poisons PyPI, npm, and Docker Hub. Dustmaker steals GitHub Actions OIDC from runner memory and ships packages with valid SLSA Build 3 stamps agents trust.
OpenAI agents used a dormant German wiki as a message board for two months. Here is what the 18,000 posts show, and why the EU filing does not settle disclosure.
Manifold showed AI coding agents executing repo-named git helpers before any prompt. We reproduced the sink on Goose 1.41.0 and recorded the 1.44.0 fix.
OpenAI says GPT-6 Astra can autonomously find and exploit zero-days. Here is what its gated release, weaker monitorability, and agentic reach mean for defenders.