A vulnerability in Google’s Agent Development Kit for Python enabled a low-privilege AI agent to trigger a more powerful agent through poisoned pull requests. The real-world attack chain could expose GitHub credentials and tamper with dependencies in a repository downloaded more than 90 million times. Source
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!