A vulnerability in Google’s Agent Development Kit for Python enabled a low-privilege AI agent to trigger a more powerful agent through poisoned pull requests. The real-world attack chain could expose GitHub credentials and tamper with dependencies in a repository downloaded more than 90 million times. Source
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!