ACVEAgent configuration vulnerability registry

ACVE-2026-0527

A threat actor used an AI coding chatbot and agent instructions to plan and execute a mass credential-harvesting campaign in less than six hours, compromising thousands of third-party credentials.

Exposure

Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

Claims on this page have not been checked against primary sources.

Description

Threat

user · unsafe-default · exfiltration

What

GTIG says a threat actor used an AI coding chatbot, a prompt and preconfigured agent instructions to plan, build and execute a mass credential-harvesting campaign in under six hours. The campaign compromised thousands of third-party credentials.

Detection

GTIG reported the activity in its Q2 2026 threat tracker. Recorded from Google Threat Intelligence Group's report. Not recreated in a lab.

Fix

Keep credential-harvesting workflows out of agent reach, require review for high-impact actions, and monitor automated use of exposed cloud resources.

Fix

The operator was the attacker, so victims depend on the model provider and the cloud provider detecting and cutting off the campaign.

  • Reconfigure chatbot-provider.misuseDetection to detects and cuts off accounts building credential-harvesting campaigns. Recommended: an AI coding chatbot helped plan, build and run the campaign in under six hours. Owner: model-provider
  • Reconfigure cloud-provider.abuseDetection to detects mass scanning from a compromised resource. Recommended: the campaign used a compromised cloud resource. Owner: infra-provider

References

REPORT

Report a problemJSON