← Back
OtherSANS Internet Storm Center·2 hours ago

The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)

A researcher's internet-exposed LLM inference honeypot was discovered and repurposed by attackers as a "free" backend service, where it received requests from a real coding-agent session containing sensitive data including command history, filesystem output, and local tool manifests. The incident demonstrates how threat actors could exploit such positions to intercept and manipulate agent interactions, gaining visibility into operational details and potential execution capabilities without needing to trigger actions themselves.

Read full article at SANS Internet Storm Center

Related Articles

OtherThe Hacker News·8 hours ago

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept

OtherHelp Net Security·14 hours ago

The OpenClaw 2.0 release moves your sessions into SQLite

OpenClaw 2.0, a major update to the open source platform that automates security monitoring tasks like tracking vendor advisories and alerting users via Telegram, now stores session data in SQLite instead of previous methods. The upgrade represents the project's largest release to date and includes changes to how user data is handled within shared multiplayer workspaces. Security professionals should review the storage mechanism changes before deploying the update.