DEF CON 34: AI Agent Security Flaws & Broken Sandboxes

1h ago·0:00 listen·Source: forkast.news

Summary

New research from DEF CON 34 reveals that AI agent security issues are not simple bugs, but fundamental flaws in their design. The findings challenge the effectiveness of current corporate security products. What's interesting is that major coding agent sandboxes, like Claude Code and Gemini CLI, are fundamentally broken. For example, a Gemini CLI vulnerability scored a critical CVSS 10.0, showing that these isolation environments are porous by design. Infrastructure layers are also fragile. A presentation called "OffGuard" exposed LiteLLM, a popular open-source AI gateway, as a single point of failure. Researchers demonstrated how to achieve full cloud compromise, even finding that nearly one in ten instances accepted default credentials or required no authentication. Connectivity is another major problem. Analysis of over 19,000 servers found that security features are easily bypassed, turning tools meant to connect agents to data into conduits for attackers. New threats include manipulating trust between agents. An attacker can trick one agent into escalating the privileges of another through authorized calls. Low-level exploitation of the infrastructure is also possible, as a PyTorch vulnerability allowed remote compromise of several AI applications. The bottom line is that these structural design gaps create significant risks for anyone relying on AI agent systems.

Read the full article on forkast.news

This is an AI-generated audio summary. Always check the original source for complete reporting.

Share
Keep Listening