chiprook
← Security
SecuritySeptember 28, 2026, 17:27

Darktrace: AI agent history is unsigned and writable by anyone

Darktrace's Signal Labs demonstrated conversation history poisoning: a malicious package or any process with write access injects a fabricated session into the harness's local database, and the model treats it as trusted context. All four tested harnesses (Claude Code, Codex, Kiro-CLI, Pi) accepted the fake history, with full Active Directory compromise reached in the lab. There is no client-side patch; researchers propose cryptographically signing every model response and verifying it server-side.

Darktrace: AI agent history is unsigned and writable by anyone
#Darktrace#Anthropic#OpenAI#Claude
Read next
Security

Darktrace: history poisoning turns coding agents into attackers

Security

Darktrace CEO: AI Agents Are the New 'Insider Threat'

Security

Darktrace makes SECURE AI generally available to monitor enterprise AI use

Security

Anthropic reports autonomous AI-agent attacks as physical AI security demand grows