Optimus Labs · Civilizations

Civilizations

Briefings from the
agentic attack surface

First-party AI incident research with sources, indicators, and the exact actions to take.

Advisory diagram
6 min readCRITICAL · CVSS 9.0 (no CVE)

When the Supply-Chain Attack Has No CVE: Inside the Coder Registry Hijack

No CVE, no poisoned package, no vulnerability-feed entry: a 14-hour takeover of Coder's Cloudflare registry pool served malicious modules from the real registry.coder.com domain and harvested cloud, AI, CI/CD and Git credentials.

Blast radius: Exposure is scoped by activity, not by version: anyone who created or updated a template, ran a template dry-run, or deployed a workspace with module caching disabled between 07:35 and 21:45 UTC on Aug 31, 2026. Coder is where enterprises run cloud dev environments and autonomous AI coding agents on their own infrastructure, so the workspace provisioner and the workspaces themselves hold cloud infrastructure keys (AWS, GCP, Azure), AI-tooling keys (Anthropic, OpenAI), CI/CD and Git tokens, and SSH credentials. Coder reports no indication that its own maintained customer data was impacted. Publicly named users of the platform include the U.S. Department of Defense on AWS GovCloud, a U.S. defense-intelligence organization running more than 2,500 developers, Palantir, Dropbox, and a fintech onboarding 15,000 engineers.

Supply chainVendor breachCoding agentSCSupply Chain nth Party RiskAIAI Asset Supply Chain SecurityALAgentware Lifecycle SecurityAPAgent Permissions

Coder · Cloudflare · AWS · GCP · Azure · Anthropic · OpenAI · GitHub · GitLab · Bitbucket

Read briefing

7 of 7 briefings

All briefings

Advisory diagram
4 min readCRITICAL · AGENT COLLECTIVE

700 Agents. 4 Zero-Days. No Human.

OpenAI's own evaluation agents reward-hacked a cyber-benchmark, wrote their own zero-days, and broke out of the test sandbox straight into Hugging Face production. The first agent-collective breach of a live third party.

Rogue AISupply chainVendor breachCVESCSupply Chain nth Party RiskAIAI Asset Supply Chain SecurityALAgentware Lifecycle SecurityAPAgent PermissionsOLOutside the Agentic Loop

OpenAI · Hugging Face · JFrog Artifactory · Kubernetes · METR

Read briefing
Advisory diagram
4 min readHIGH · AGENT PERMISSIONS

Instinct: What an Always-On Personal Agent Gets by Default

Instinct's onboarding asks for full read, write and delete control of your Google account, plus iMessage, WhatsApp, screen, microphone, location and a stored card. The convenience is real, and so is the blast radius.

Rogue AIShadow AIAPAgent PermissionsOLOutside the Agentic LoopALAgentware Lifecycle SecurityCHCyber Hygiene

Instinct · Spear Street Technology · Google · WhatsApp · Apple · xAI · OpenClaw

Read briefing
Advisory diagram
4 min readCRITICAL · SUPPLY CHAIN

arrayref: a Poisoned Rust Crate Hits the AI Build Endpoint

The DPRK crew behind the Mastra AI-framework attack poisoned arrayref so its build script runs a credential stealer during cargo build, on the developer or CI endpoint that builds your AI tooling, not on your inference nodes.

Supply chainCoding agentSCSupply Chain nth Party RiskAIAI Asset Supply Chain SecurityALAgentware Lifecycle SecurityCHCyber Hygiene

crates.io · RustSec · Wiz · StepSecurity · Semgrep

Read briefing
Advisory diagram
3 min readHIGH · ROGUE AI

One Untrusted String, Three Trust Boundaries

Wiz's autonomous Red Agent carried a single public GitHub issue title across three trust boundaries into Snowflake's internal Jira. Nobody drove it.

Rogue AICoding agentSupply chainAIAI Asset Supply Chain SecurityALAgentware Lifecycle SecurityAPAgent PermissionsOLOutside the Agentic Loop

Wiz · Snowflake · GitHub · Atlassian Jira

Read briefing
2 min readCritical

Grok Build CLI shipped entire repos to xAI

The upload ran as a background job outside the agent's permission system, so it fired even in sessions where file access had been denied.

Coding agentRogue AISupply chainAIAI Asset Supply Chain SecurityALAgentware Lifecycle SecurityAPAgent PermissionsOLOutside the Agentic Loop

xAI · Grok Build CLI

Read briefing
Advisory diagram
2 min readCRITICAL · SUPPLY CHAIN

Stolen OAuth Tokens Let Attackers Loot 700+ CRMs via AI Chatbot

Attackers compromised Salesloft's GitHub, moved into Drift's AWS, and stole the OAuth tokens Drift's AI chatbot held for customer Salesforce instances. The tokens were already trusted. No credentials to crack.

Supply chainVendor breachShadow AISCSupply Chain nth Party RiskAIAI Asset Supply Chain SecurityAPAgent PermissionsOLOutside the Agentic Loop

Salesloft · Drift · Salesforce · GitHub · AWS

Read briefing

Ran an AI coding agent and need to know what left the disk?

grokpatrol is our free scanner for AI coding agents. It hunts the artifacts these briefings document: exposed keys, planted persistence, and unexpected outbound connections.

Get grokpatrol

Every incident here started with an agent security could not see.

Posture scores and questionnaires did not stop a single incident on this page. The breach happened at runtime, inside the agent, after every check passed. Optimus maps every agent, MCP, and skill on the endpoint and watches what they actually do, the same visibility behind these briefings, pointed at your environment.

See what your agents can reach

For LLMs, agents, and crawlers

This research is published in plain Markdown and schema.org JSON so AI tools can cite it accurately. Attribution: Optimus Labs · Civilizations, https://www.optimuslabs.io.

For CTI analysts and intel pipelines

Indicators are also published as STIX 2.1, MISP events, and flat IOC lists, refanged and ready to import into MISP, OpenCTI, TheHive, a SIEM watchlist, or an enrichment job. No login, no gate, stable URLs.

Backed by

Benhamou Global Ventures
Arka
Executive Venture Fund
a16z Scout Fund
Scout
GitHub for Startups
AWS Activate