A vulnerability in Google’s Agent Development Kit for Python enabled a low-privilege AI agent to trigger a more powerful agent through poisoned pull requests. The real-world attack chain could expose GitHub credentials and tamper with dependencies in a repository downloaded more than 90 million times. Source
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!