Kryptovaluta-ticker:
sysadmin fra Cyber Security News

A Malicious GitHub Issue Could Turn Google’s AI Agent Against Its Own CI/CD Pipeline

Guru Baran
Tuesday at 09:46
5 Visninger
0 Kommentarer
A Malicious GitHub Issue Could Turn Google’s AI Agent Against Its Own CI/CD Pipeline

A first practical, real-world case of agent-to-agent exploitation inside a production multi-agent system, a novel attack class that turns one AI agent against another to compromise a software supply chain. The flaw was found in google/adk-python, the repository behind Google’s Agent Development Kit for Python, an SDK widely used by developers to build their own AI agents. The adk-python repository ran two tiers of automated AI agents. A low-privileged agent handled public-facing interactions, triggered whenever a user opened a pull request or issue, while a high-privileged agent was reserved for trusted maintainers with real authority over the codebase. Pillar’s researchers discovered that the low-privileged,...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!