ACVE-2026-0527
A threat actor used an AI coding chatbot and agent instructions to plan and execute a mass credential-harvesting campaign in less than six hours, compromising thousands of third-party credentials.
Exposure
Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
Claims on this page have not been checked against primary sources.
Description
Threat
user · unsafe-default · exfiltration
What
GTIG says a threat actor used an AI coding chatbot, a prompt and preconfigured agent instructions to plan, build and execute a mass credential-harvesting campaign in under six hours. The campaign compromised thousands of third-party credentials.
Detection
GTIG reported the activity in its Q2 2026 threat tracker. Recorded from Google Threat Intelligence Group's report. Not recreated in a lab.
Fix
Keep credential-harvesting workflows out of agent reach, require review for high-impact actions, and monitor automated use of exposed cloud resources.
Fix
The operator was the attacker, so victims depend on the model provider and the cloud provider detecting and cutting off the campaign.
- Reconfigure
chatbot-provider.misuseDetectiontodetects and cuts off accounts building credential-harvesting campaigns. Recommended: an AI coding chatbot helped plan, build and run the campaign in under six hours. Owner: model-provider - Reconfigure
cloud-provider.abuseDetectiontodetects mass scanning from a compromised resource. Recommended: the campaign used a compromised cloud resource. Owner: infra-provider