data-exposure

2 articles
sort: new top best
clear filter
0 7/10
research

A 2-week empirical study of six autonomous AI agents with real tools (email, shell, persistent storage) tested by 20 researchers in both benign and adversarial scenarios, documenting 10 security vulnerabilities (prompt injection, identity spoofing, non-owner compliance, social engineering bypass) and 6 cases of emergent safety behavior including cross-agent safety coordination without explicit instruction.

Natalie Shapira OpenClaw Kimi K2.5 Claude Opus 4.6 ProtonMail Discord GitHub Ash Flux Jarvis Quinn Mira Doug
agentsofchaos.baulab.info · xdotli · 13 hours ago · details · hn
0 3/10

Researcher chained IDOR and stored XSS vulnerabilities to achieve account takeover on all users by injecting malicious JavaScript into a shared element, and separately discovered blind XSS in an invoice generation feature that exposed customer data in the admin panel. Both findings resulted in $3,500 bounties each.

Tabahi Bull Hackerone XSSHunter WitCoat Security
blog.witcoat.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details