
#29: Machines Leave Footprints
Top Story: Attackers let agents run connected parts of an operation — Google Threat Intelligence Group documented a financially motivated actor that compromised a cloud environment, then used an AI coding chatbot, a prompt and predefined agent instructions to build a credential-harvesting operation in less than six hours. A software package registry became infrastructure for an AI evaluation that reached the real internet. — Nightingale Collective linked more than 100 packages from May's GemStuffer campaign to a path that made RubyDoc.info run code, retrieve public government data and publish the results back to RubyGems. AI helped turn a messaging-app flaw into a worm demonstration in days. — Calif says its team found a memory-corruption bug in WeChat and produced the first remote-control exploit in about two days, then built a polished worm over another week. Four evaluation agents reached real systems after test environments mistakenly retained internet access. — Anthropic's expanded review covered roughly 481 million transcripts, reidentified the four known incidents and found no others of similar or worse severity. The frontier-model debate moved from employee alarm to an operational commitment. — Former OpenAI and Anthropic pretraining researcher Jacob Coxon resigned, accusing both labs of racing toward self-improving AI without adequate safeguards. Anthropic says AI has moved from assistant to orchestrator in observed cyber operations. — Its September report describes multi-agent workflows performing reconnaissance, exploitation, rebuilding and data exfiltration, while humans still selected targets and reviewed stolen data. A $25 million funding round puts human and agent access into the same graph. — Cymphony emerged with $30 million in total funding and a platform that combines identity, data and activity signals for employees, agents and other non-human identities. NVIDIA tightened how NemoClaw carries credentials and policy across sandbox operations. — The September 11 release exports references to credentials rather than secret values, validates external-component declarations before gateway changes and checks sandbox identity and effective policy before activation. DriftNet found that an agent's sequence of tool calls can reveal where its behavior changed. — The research system analyzes logged action trajectories, flags whether the run was compromised and labels the point where a hidden instruction entered. Agent-to-agent delegation creates security boundaries that a single-agent log cannot show. — A2ABreak translated the A2A specification into a state model and identified 11 weaknesses involving lost identity, injected context and unverified capability claims. Tool descriptions alone may reveal unsafe designs before an agent runs. — MCPSEC evaluated 177 tools across 20 MCP servers and correctly predicted 94 of 95 human-confirmed prompt-injection risks. A frontier-model audit produced two Datasette security releases with two humans reviewing each fix. — The maintainers used several coding agents to investigate related flaws, then split regression-test writing and implementation between two people. Gartner Security & Risk Management Summit, September 22–24, London. — The agenda includes AI's impact on cybersecurity, governance and deepfake identity impersonation alongside broader risk and resilience sessions.. Curator's Corner: Machines Leave Footprints Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-09-14.html
- Transcript