Agents hooked into GitHub can steal creds – but Anthropic, Google, and Microsoft haven't warned users
Exclusive Security researchers hijacked three popular AI agents that integrate with GitHub Actions by using a new type of prompt injection attack to steal API keys and access tokens, and the vendors who run agents didn't disclose the problem....