LATIDIA · Ciberseguridad
AgentXploit: Autonomous Repository-to-Runtime Red-Teaming for AI Agents
arXiv:2609.31318v1 Tipo de anuncio: nuevo Resumen: los agentes de IA combinan modelos de lenguaje con datos externos y herramientas que pueden modificar archivos, llamar a API o ejecutar código. Las fallas de seguridad pueden surgir cuando el contenido adversarial cambia
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.31318v1 Announce Type: new Abstract: AI agents combine language models with external data and tools that can modify files, call APIs, or execute code. Security failures can arise when adversarial content changes an agent's tool use or when the surrounding software contains vulnerabilities such as path traversal or command injection. We study authorized white-box pre-deployment auditing, where the auditor has access to the target repository and a controlled runtime, but successful attacks must still act through the task-defined attacker interface and be confirmed by an external verifier. We present AgentXploit, a two-role auditing system that separates repository-level attack-path discovery from runtime exploitation. The Analyzer Agent traces attacker-controlled inputs to sensitive