Five plead guilty in latest federal ATM jackpotting case
Five Venezuelan nationals have pleaded guilty in a federal case involving ATM jackpotting, a technique where criminals manipulate ATMs to dispense cash without authorization. The guilty pleas underscore ongoing law enforcement efforts to combat organized jackpotting gangs that continue to pose a threat to financial infrastructure.
A researcher's internet-exposed LLM inference honeypot was discovered and repurposed by attackers as a "free" backend service, where it received requests from a real coding-agent session containing sensitive data including command history, filesystem output, and local tool manifests. The incident demonstrates how threat actors could exploit such positions to intercept and manipulate agent interactions, gaining visibility into operational details and potential execution capabilities without needing to trigger actions themselves.
Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness
The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept