Poisoned pull requests contain prompt injection that allows one to control another In what they call the first ever real world agent to agent exploitation method, Pillar Security researchers say they discovered an exploit in the repository behind Google Agent Development Kit for Python that could allow attackers to compromise supply chains. In other words, now we know that one AI agent can be used to control and compromise another one that has more privileges. The security snafu existed in...

Read the full article at The Register