United States
AI agents from major firms vulnerable to credential theft
Wednesday, 15 April 2026 at 12:00 UTC · 1 source
Security researchers have demonstrated that AI agents from major firms—Anthropic's Claude, Google's Gemini, and Microsoft's Copilot—are vulnerable to credential theft when integrated with platforms like GitHub. The structural flaw allows malicious instructions hidden in external content, such as repositories or pull requests, to redirect the agents' actions and exfiltrate user data without detection. All three vendors have reportedly issued minimal bug bounty payouts for the findings but have not published public advisories to warn users. The researchers assess this type of vulnerability is likely pervasive across similar AI agent integrations.
Key Details
Vulnerable agents: Anthropic Claude, Google Gemini, Microsoft Copilot
Attack vector: Prompt injection via platform integrations (e.g., GitHub)
Vendor response: Minimal bounty payouts, no public advisories issued
Sources
Cycle: Wednesday, 15 April 2026 at 12:00 UTC · First reported: 4h ago