enterprise data management

AI agents leak secrets when credential security is overlooked

Recent hacks of major AI coding agents—Claude Code, Codex, and Copilot—underscore a critical vulnerability: attackers targeted credentials, not models.

3 min readVentureBeat
AI agents leak secrets when credential security is overlooked

The recent exploits targeting AI coding assistants like Codex, Claude Code, and Copilot underscore a significant and growing vulnerability within enterprise AI systems. Attackers have consistently aimed for credentials rather than the models themselves, exploiting gaps in security that have persisted despite the industry's rapid advancements. This troubling trend reflects a broader issue within AI development, where the rush to innovate often overshadows essential security practices. For those keen on understanding the implications of these incidents, the parallels with previous security failures are stark, particularly highlighted in articles such as One command turns any open-source repo into an AI agent backdoor. OpenClaw proved no supply-chain scanner has a detection category for it and 5,000 vibe-coded apps just proved shadow AI is the new S3 bucket crisis.

What makes these breaches particularly alarming is the methodical nature of the exploits. Each incident followed a similar pattern: an AI coding agent executed an action using credentials it held, bypassing security measures that should have been in place. For instance, in the case of Codex, a crafted GitHub branch name was able to exfiltrate an OAuth token due to a lack of input sanitization. This not only demonstrates a technical oversight but also raises critical questions about how organizations are vetting and managing the AI tools they integrate into their workflows. As Merritt Baer, CSO at Enkrypt AI, aptly pointed out, many enterprises are mistakenly approving interfaces rather than scrutinizing the underlying systems that support them.

The implications of these vulnerabilities extend beyond the immediate risk of credential theft. They highlight a systemic governance gap in how organizations oversee AI identities and permissions. Currently, most companies have robust measures for managing human identities but lack equivalent oversight for AI agents. This disparity puts enterprises at risk of not only credential exploitation but also potential data breaches that could arise from unchecked AI behavior. The need for comprehensive identity management frameworks that include AI agents is more urgent than ever. As emphasized in another relevant piece, Anthropic Skill scanners passed every check. The malicious code rode in on a test file, reliance on automated security assessments without human oversight can lead to catastrophic failures.

Looking ahead, the industry must confront the reality that security in AI systems cannot be an afterthought. Organizations need to establish rigorous governance protocols for AI agents akin to those they have for human users. This includes routine audits of OAuth scopes, credential management, and ensuring that agents operate on a principle of least privilege. As we navigate this new landscape, a fundamental question emerges: How can enterprises effectively balance the speed of technological advancement with the necessity for robust security measures? The answers will define the future of AI integration in business and dictate the level of risk organizations are willing to accept.

From VentureBeat

On March 30, BeyondTrust proved that a crafted GitHub branch name could steal Codex’s OAuth token in cleartext. OpenAI classified it Critical P1. Two days later, Anthropic’s Claude Code source code spilled onto the public npm registry, and within hours, Adversa found Claude Code silently ignored its own deny rules once a command exceeded 50 subcommands. These were not isolated bugs. They were the latest in a nine-month run: six research teams disclosed exploits against Codex, Claude Code, Copilot, and Vertex AI, and every exploit followed the same pattern. An AI coding agent held a credential, executed an action, and…

Read the original at VentureBeat