DevCybersecurity4 min reading time

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

The Hacker News
Read full post
Google removed three AI agent workflows from its Agent Development Kit Python repository after security researchers revealed a vulnerability that allowed a public GitHub issue to manipulate a triage agent into triggering a privileged code-fixing agent, risking arbitrary code execution and credential exposure. The flaw involved a trusted bot identity bypassing authorization checks, though no in-the-wild exploitation has been reported.

More in Dev

Introducing the Agents API

Covered by 3 sources
Dev1 min read

Native is now the future of mobile at Shopify

Simon Willison's Weblog
Dev5 min read

AWS open-sources Pizza Bot: email-style inbox for background AI agents

The New Stack (AI)