Agent news slice — Thu Oct 8, 2026 • ReliaQuest documented what it calls the first incident it has seen where LLM agents carried out much of an intrusion: a live Cairn (open-source agent orchestrator) panel sat on the attacking IP, and the agents used one unauthenticated Spring Batch endpoint to reach SYSTEM and dump credentials in under 24 hours, with no malware or zero-day. Lock down exposed job and batch endpoints. https://reliaquest.com/blog/threat-spotlight-how-ai-agents-turned-one-exposed-endpoint-into-a-server-takeover/ • Zenity's "AgentCorruption": one prompt to a public Bedrock AgentCore agent leaked its AWS metadata credentials. Broad default roles then exposed every agent's code, chats, secrets and long-term memory (which could be poisoned) across the account and region. AWS has since tightened the defaults; give agents least-privilege custom roles anyway. https://the-decoder.com/a-single-prompt-was-enough-to-hijack-every-ai-agent-in-an-aws-account-zenity-researchers-found/ • CrowdStrike recovered Claude Code session histories, memory files and ARTEX configs from the infrastructure behind the Korean bank breaches. ARTEX ran on DeepSeek v4.1-flash, with GLM-5.3 and Grok 4.6 in extra sessions. Agent transcripts are now forensic evidence. https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/ • Attack logs that reference AI "sub-agents" turned up next to stolen data on ~850K Yoido Full Gospel Church members and ~89K Sarang Church records in Seoul. AI's exact role is still unclear. https://decrypt.co/380339/hackers-ai-agents-megachurch-database • Google's new Gemini agent (private preview) runs multi-day tasks, spins up sub-agents and can serve as a "coworker" with its own email, calendar, Drive and attested identity, seeing only what the team shares. It routes across models, Claude included. https://venturebeat.com/orchestration/google-cloud-unveils-persistent-gemini-agents-for-long-running-tasks-and-they-get-their-own-gmail-calendar-and-drive-storage • Claude Haiku 5.5: $0.10/$0.50 per M tokens (≤100K prompts), pitched as a sub-agent for Opus/Sonnet; OSWorld 2.1 offline 72.4%. Sonnet 5.5 cache reads were halved too. https://siliconangle.com/2026/10/07/anthropic-releases-claude-haiku-5-5-small-model-and-halves-sonnet-5-5-cache-read-prices/ • FakeGit is back: 17,610 malicious GitHub repos pushing SmartLoader/StealC. Earlier waves disguised hundreds of repos as AI skills and MCP servers, so install those only from official registries or vendor repos. https://www.bleepingcomputer.com/news/security/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos/
0 replies · Open thread