Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Amazon increases AI infrastructure spending to $220bn this year

    July 30, 2026

    A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

    July 30, 2026

    DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

    July 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Amazon increases AI infrastructure spending to $220bn this year
    • A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
    • DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
    • Why 37 million Celsius bankruptcy shares are blocked from an immediate cash-out despite Nasdaq debut
    • Mammals moving between the Americas stopped over in Mexico
    • The Guardian view on sporting fair play: it was never quite cricket | Editorial
    • UN launches hunt for next chief amid rising challenges | United Nations News
    • Potential roadblocks ahead for Graham-led Russia sanctions bill
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, July 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    AI Harnesses Burst With Potential Exploit Opps

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 30, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Major frontier AI vendors — including Anthropic, Google, and OpenAI — need to rein in the harnesses they wrap around their large language modules, to limit security weaknesses created by software components that are too trusting of each other.

    That’s the word from researchers at AI penetration testing firm Novee Security, who were able to use Google’s AI agent to execute a supply chain attack and write to its own repository on GitHub, says Elad Meged, a founding team and security researcher at the company. The team also found issues in Anthropic’s and OpenAI’s AI agents by exploiting misalignments in the trust between elements to enable attacks.

    AI harnesses are the software frameworks that provide tools, memory and guardrails for managing AI models; components can include functions like context management, tool integration, and feedback loops too. When a company adopts an AI agent and makes it part of their infrastructure, they are also adopting the trust assumptions of all of those components as well, Meged explains.

    Related:OpenAI’s Rogue Model Claims More Victims Beyond Hugging Face

    “People aren’t aware of the amount of code and the amount of trust that they are embedding into their own systems when they’re adopting an agent,” he says. “You don’t know what code is in there, you don’t know what it’s able to do, and the more trust people give to the agents, the more vulnerable they can be.”

    The warning comes as companies increasingly adopt AI agents to benefit from their complex automation capabilities and concerns over the security and safety of those agents continues to rise. Earlier this month, the testing of a new pre-release OpenAI model resulted in the model escaping its sandboxed environment, finding a vulnerability in the only accessible software — a package management system — and attacking Hugging Face. At the Black Hat USA conference last year, researchers demonstrated ways of completely altering AI agent behavior using prompt injection and vulnerabilities. Since then, the foundational model makers have invested in additional layers of security, most often implemented as part of alignment or in the harness, but also increasingly through isolation such as containers. However, those defensive measures do not necessarily take into account the ability of attackers to co-opt the legitimate software surrounding the AI model as part of the harness.

    Trust Boundaries & AI Harnesses

    Harnesses consist of software, and often reusable skills or packages from open source projects, which are easily scannable and historically prone to vulnerabilities and misconfigurations. In addition, the harnesses and system prompts encapsulating AI agents are often not transparent, leaving companies that adopt AI agents to tacitly accept many unknown risks, arguably chief among them the lack of visibility into how the software scaffolding around the agent — the “harness” — works.

    Related:When AppSec Scanners Become a Supply Chain Attack Vector

    Overall, the risks are twofold: At one end, AI agents rely on traditional software technology to do things — software that has its own vulnerabilities — while at the other, interactions between harness components may result in losing track of the whether inputs are trusted or not. While vendors have added security around their models and harnesses, how harness components interact have largely been overlooked, according to Novee Security.

    “The vendors aren’t careless,” the company said. “Anthropic built dozens of security checks, Google built multiple execution modes with environment sanitization, and OpenAI built a sandbox with protected paths. The defenses are there; they fail at the handoffs between components.”

    Companies need to understand that adopting an AI agent means that all the components of the harness becomes part of the infrastructure, the company stated in a yet-to-be-published white paper shared with Dark Reading.

    Related:When AI Agents Escape Sandboxes, Old Security Rules Apply

    Time to Audit the Agents

    Unfortunately, companies are not investing enough resources into securing the agents that they are running. While 80% of companies run AI agents, only 47% have security controls in place to manage their risks, according to a study published in early 2026. Companies should analyze their AI agents and require that vendors be transparent about the code used, says Meged.

    “Read the code, understand where the data flow and the code flow are going to, and try to find this mismatch into some sinks or something that can be dangerous,” he says. “It can lead as many places where code execution is possible.”

    For now, harness security is still in its infancy. and attackers may have the advantage for a while, Meged says.

    “You can raise your detection level, but in my opinion, attackers will always have a way to sneak in — this is the race attackers know well,” he says.

    Meged will present details of the security weaknesses in major vendors’ harness during his session at the Black Hat USA conference.

    Burst exploit Harnesses Opps potential
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

    Potential roadblocks ahead for Graham-led Russia sanctions bill

    VMware fixes three critical flaws allowing auth bypass, VM escapes

    Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers

    Timeless Compliance: Why Better Questions Beat Bigger Frameworks

    ShinyHunters claims Brinks Home breach, threatens to leak stolen data

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Amazon increases AI infrastructure spending to $220bn this year

    July 30, 2026

    A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

    July 30, 2026

    DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

    July 30, 2026

    Why 37 million Celsius bankruptcy shares are blocked from an immediate cash-out despite Nasdaq debut

    July 30, 2026
    Latest Posts

    Advancing the next era of national science

    July 22, 2026

    Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

    July 22, 2026

    Most bus fares in England to be capped at £2 from January

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Amazon increases AI infrastructure spending to $220bn this year

    July 30, 2026

    A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

    July 30, 2026

    DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

    July 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.