Security researchers and vendors warned that autonomous AI agents can be manipulated into leaking secrets and misusing privileged access, turning them into a new pathway for credential theft and system compromise. Reporting from SC Media cited Okta Threat Intelligence research showing agents on the OpenClaw platform could be socially engineered or prompt-injected into exposing passwords, API keys, GitHub tokens, and OAuth refresh tokens, while other analysis described a confused deputy problem in which malicious text embedded in files, logs, web pages, or instruction files causes agents to execute higher-trust actions with their legitimate permissions. The risk is amplified when agents can read local files, edit code, run commands, fetch remote content, and access external tools or MCP servers without strong separation between trusted instructions and untrusted data.
Defenders are responding with controls aimed at limiting agent authority and reducing secret exposure. Help Net Security reported on Nono, an open-source sandbox that constrains AI coding agents at the kernel level using mechanisms such as Landlock on Linux and Seatbelt on macOS, while introducing scoped tool permissions and proxy-mediated "phantom credentials" so agents do not directly handle live secrets. The broader guidance aligns with established ATT&CK techniques including T1552 Unsecured Credentials and T1546 Event Triggered Execution, emphasizing least privilege, centralized identity governance, short-lived credentials, secure secret storage, logging, rapid revocation, provenance checks, input isolation, and human approval to prevent agents from becoming a bridge to sensitive systems and cloud resources.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
SC Media cites Okta Threat Intelligence research showing AI agents on the OpenClaw platform could be socially engineered or prompt-injected into revealing passwords, API keys, GitHub tokens, and OAuth refresh tokens.
A July 27, 2026 blog post describes how AI agents can be hijacked through prompt injection and frames the issue as a confused deputy problem caused by mixing trusted instructions with untrusted data.
Help Net Security reports on Nono, an open-source runtime that confines AI coding agents with kernel-level controls and scoped tool permissions to reduce access to files, credentials, and production systems.
A July 24, 2026 reference discusses whether observed Codex behavior resembles malware, indicating technical scrutiny of credential access and syscall-trace activity.
MITRE ATT&CK notes that applying Microsoft patch KB2962486 prevents credentials from being stored in Group Policy Preferences, reducing exposure of unsecured credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
meetcyber.net
Open sourcescworld.com
Open sourcemeltedinhex.com
Open sourcemeltedinhex.com
Open sourcemeetcyber.net
Open sourcehelpnetsecurity.com
Open sourcegrith.ai
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.