AI · 45 days ago
The control point in AI agents is no longer the model prompt. In these flaws, forged tool calls could reach dispatch logic without a legitimate model turn, so the safety layer you expected to approve action never actually got a vote.
The report ties that pattern across Amazon Bedrock AgentCore’s InvokeHarness API, Google’s ADK for Python, and Vercel’s AI SDK harnesses for Codex and OpenCode. AWS fixed the managed service, Google issued ADK 2.5.0, and Vercel patched @ai-sdk/harness-codex 1.0.29 and @ai-sdk/harness-opencode 1.0.28.
The same shift shows up in related testing incidents and token-jacking cases: once agents hold API keys or can reach outside systems, stolen tokens and model escapes turn the agent’s own reach into the blast radius. Prompt hardening does not cover that failure mode.
11 sources covering this story
Autonomous AI attacks pose 'clear and present danger' to critical infrastructure
Weaponized agents could turn digital intrusions into kinetic disasters, experts warn
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan
Israeli cyber firm Dream said the framework adapted mid-operation, corrected its mistakes and expanded as it went along.
Hackers abuse AI models to find new entry paths
Network defenders are racing to secure their IT systems before criminal and state-actors circumvent existing guardrails.
Security leaders’ rogue AI confidence could actually be disastrous
IT and security leaders believe they can detect when an AI agent malfunctions or operates out of scope, but few can quickly trace and contain the cascading impact.
The AI safety test is becoming a safety risk | TechCrunch
AI agents are escaping cybersecurity testing environments and reaching real-world systems, raising questions about whether safety infrastructure, industry standards, and regulation can keep pace with increasingly powerful models.
The Record from Recorded Future
Irregular, firm behind AI hacking incidents, won't say if there were more
A spokesperson said Irregular’s investigation into what happened with Anthropic, OpenAI and Meta's AI models was ongoing and that they could not “go into further details.”
Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident
One of Meta’s AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI systems
AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
AI agent flaws in AWS, Google, and Vercel let forged tool calls reach tools without model authorization, while several paths skip the model entirely.
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys.
Meta AI Hacked External Systems During Cybersecurity Testing
The incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week.
AI Sends Global Crime Syndicates Into Fraud Nirvana
Organized crime is scamming at scale with AI-enabled voice cloning, deepfake video overlays, LLM-driven persona management, and automated translation.
Part of the PlainSec briefing for 2026-08-17