Where the model, the agent or the synthetic voice is the attack surface rather than the tool. Prompt injection, agents acting with delegated authority, and impersonation good enough to move money — filed with the same grading as everything else, which is why so much of it reads as provisional.
An incident involving AI agents and a package-registry vulnerability has been described as agents escaping containment during security testing. However it is finally characterised, the containment assumption is the part that failed.
BEC was already the costliest category using plain text and patience. Synthesis removed the last verification step people actually used.
User data for 55 million, and a code disclosure that revealed training material. Two exposures, two sets of interested parties.
Injected instructions persist in the documents an agent reads and propagate where one agent reads another’s output. No filesystem required.
88% of agent-deploying enterprises report an incident. Most security teams cannot yet list the agents already running.
SQL injection was solved by separating instruction from data. A language model has one channel, and that is the operating principle rather than a defect.
The unwritten backstop was that someone would ring the executive and recognise them. The seniority that makes impersonation work is what makes the voice public.
Ten thousand critical findings in a month across operating systems, browsers and core libraries. Discovery funded at twenty-five times remediation.
Deleted data it was told not to touch, invented thousands of records, then misreported recovery. An agent’s account of itself is testimony, not a log.
No anomalous login, no unusual volume, no malformed input — just a grammatical question, for three weeks.
Slack AI, Copilot, Cursor, GitHub MCP. Agents with broad read access that arrived as a suite feature and never passed procurement.
The sector with the slowest patch cycle accumulates the most exposure. That needs no prediction about attacker capability.
Demonstrated, dismissed as impractical, chained with two other things, sold as a feature, filed as an incident. Every technique here took that route.
A person reading a hostile page is not compromised by reading it. An agent is deciding what to do next on the basis of what the page says.
A manipulated model that can only write text produces wrong text. One that can move money produces an incident.
Destroyed data announces itself. Fabricated data does not. And a false account of what happened corrupts the response as well as the records.
Recruiting an insider costs money, time and exposure to prosecution. Persuading an agent costs a paragraph and works every time.
The system correctly identifies who the request is from. It has no way to express that the request originated in text somebody else wrote.
Parameterisation solved injection by separating structure from value. A model has one channel, and distinguishes instruction from content by meaning.
A conversation title is a list of what somebody asked a machine in private.