The break is no longer a single poisoned file or one bad assistant prompt. Malicious state can now live in shared agent configs, retained prompt logs, and built-in assistants that keep working across sessions, so standard code-review and account-security checks miss the place where access now persists.
Talos’ prompt-log analysis found attackers splitting harmful work across multiple sessions and files, claiming ownership, and writing blanket approval into persistent memory and config files across Claude Code, Codex, Cursor, and Gemini. Separate reporting shows poisoned agent instruction files can exfiltrate prompts and credentials, built-in email assistants can be used to impersonate trusted employees and hide activity, and Google’s ADK workflows exposed how a trusted bot identity can bridge an untrusted issue into privileged automation. Unit 42’s NOVA report adds the other side of the same shift: frontier AI is now industrializing vulnerability discovery, with 14,090 confirmed flaws found across 3,915 open-source projects in two months.
The result is a broader and more transferable attack model than the old “AI abuse” anecdotes suggested. If your assistants read mail, issues, or repos and keep state, the control problem is now in the prompts and memory as much as in code or credentials, and AI is also compressing the window between finding bugs and turning them into weaponized targets.