AI agent framework flaws hit 7,000 servers | VentureBeat

https://images.ctfassets.net/jdtwqhzvc2n1/5CFo8mBoW1WjItcZvYyHpg/3172659c88b4856fe7137de54672ab16/hero.png?w=800&q=75

Your AI agent did exactly what it was designed to do. The framework underneath it just handed an attacker a shell on the box that holds your OpenAI key, your database credentials, and your CRM tokens.

That is not a hypothetical. In a few months, three of the most widely deployed AI agent frameworks each turned a known, ordinary bug class into a way through. Check Point Research chained a SQL injection in LangGraph’s SQLite checkpointer to full remote code execution. Tenable and VulnCheck tracked a path traversal in Langflow’s file upload endpoint to active, in-the-wild RCE. Cyera documented a path traversal in LangChain-core’s prompt loader that reads your secrets off disk. Two paths to a shell, one to your keys. They are the same bug, wearing three frameworks.

These frameworks became production infrastructure faster than anyone secured them. They store agent state, take file uploads, load prompt configs, and...

Copyright of this story solely belongs to venturebeat.com. To see the full text click HERE

Read more

http://www.techmeme.com/img/techmeme_sq328.png

OpenAI VP of Global Policy Ann O'Leary says AI policy in the US is anchored in the states and informed by California's AI transparency law passed last year

More: Claude, Daring Fireball, import chaos, Fortune, City A.M., BMI, Quartz, Android Authority, Business Insider, The American Bazaar, The Deep View, iThinkDifferent, Breitbart, Neowin, RuntimeWire, The Daily Wire, The New Stack, CNET, Inc, Fast Company, Search Engine Land, Tech Brew, Michael Tsai, PYMNTS, SiliconANGLE, Forbes, WeRSM, Search Engine Journal,

https://images.ft.com/v3/image/raw/https%3A%2F%2Fd1e00ek4ebabms.cloudfront.net%2Fproduction%2F7523a6c6-0279-42eb-b2e3-7447048a2e24.jpg?source=next-barrier-page&fit=scale-down&quality=highe...

Researchers say suspected Chinese hackers used open-source AI agents to build an autonomous hacking tool that compromised Taiwanese government websites in July

More: Claude, Daring Fireball, import chaos, Fortune, City A.M., BMI, Quartz, Android Authority, The American Bazaar, The Deep View, iThinkDifferent, Breitbart, Neowin, RuntimeWire, The Daily Wire, The New Stack, CNET, Inc, Fast Company, Search Engine Land, Tech Brew, Business Insider, Michael Tsai, PYMNTS, SiliconANGLE, Forbes, Business Insider, WeRSM, Search