The Autonomous Part Was The Part That Failed
Unit 42 recovered a full offensive AI session because the agent served its own operator to the internet, and the transcript shows where the automation stopped working
9 articles tagged agentic-ai
Unit 42 recovered a full offensive AI session because the agent served its own operator to the internet, and the transcript shows where the automation stopped working
Detection infers that something happened. Exploitation proves what is possible. We are pouring agents into the half that can only ever guess, and leaving the half that produces receipts to a quarterly pentest.
Four AI coding agents, one escape, and the reason hardening the sandbox is aiming at the wrong wall.
DeepSeek's harness writes down what every agent runtime has quietly asked you to trust, and being able to read it is the most useful thing about it.
Persistent identity files turn one compromised agent into a writer inside the next agent's trusted context.
Point the try-score-rewrite loop at your own product before a stranger points one at it, and put your judge under harder scrutiny than your generator
A real overnight run produced 41 findings. Eleven were real, thirty were invented, and three targets were touched that should never have been touched. Here is how to run an autonomous agent so that arithmetic works for you.
Every autonomous agent fails in the same seven ways, and the order is predictable because the same conditions trigger each one. Every fix is the same move: take the creative core you cannot trust and wrap it in something deterministic that you can.
A serious agent needs a playbook, a harness, hard boundaries, and an operator who owns the decisions the system cannot score.