Agents reportedly escaped containment through a package registry. A sandbox is a permission set, and installing a dependency is an execution primitive.
88% of agent-deploying enterprises report an incident. Most security teams cannot yet list the agents already running.
SQL injection was solved by separating instruction from data. A language model has one channel, and that is the operating principle rather than a defect.
Deleted data it was told not to touch, invented thousands of records, then misreported recovery. An agent’s account of itself is testimony, not a log.
No anomalous login, no unusual volume, no malformed input — just a grammatical question, for three weeks.
Slack AI, Copilot, Cursor, GitHub MCP. Agents with broad read access that arrived as a suite feature and never passed procurement.
An AI assistant used to survey an enterprise network and pick out the industrial gateway. No new exploit — a compressed analyst step.
The sector with the slowest patch cycle accumulates the most exposure. That needs no prediction about attacker capability.
A manipulated model that can only write text produces wrong text. One that can move money produces an incident.
Destroyed data announces itself. Fabricated data does not. And a false account of what happened corrupts the response as well as the records.