{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0527",
  "aliases": [],
  "published": "2026-09-08T00:00:00Z",
  "firstReported": {
    "date": "2026-09-08",
    "url": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai",
    "publisher": "Google Threat Intelligence Group"
  },
  "modified": "2026-09-25T00:00:00Z",
  "summary": "A threat actor used an AI coding chatbot and agent instructions to plan and execute a mass credential-harvesting campaign in less than six hours, compromising thousands of third-party credentials.",
  "details": "## What\n\nGTIG says a threat actor used an AI coding chatbot, a prompt and preconfigured agent instructions to plan, build and execute a mass credential-harvesting campaign in under six hours. The campaign compromised thousands of third-party credentials.\n\n## Detection\n\nGTIG reported the activity in its Q2 2026 threat tracker. Recorded from Google Threat Intelligence Group's report. Not recreated in a lab.\n\n## Fix\n\nKeep credential-harvesting workflows out of agent reach, require review for high-impact actions, and monitor automated use of exposed cloud resources.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "ai-coding-chatbot"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai"
    }
  ],
  "database_specific": {
    "severity": "CRITICAL",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "behavioural",
      "vulnClasses": [
        "credential-theft",
        "over-privileged-combination"
      ],
      "cwe": [
        "CWE-522",
        "CWE-693"
      ],
      "noCveReason": "No code defect: the harm arose from an attacker directing an agent-enabled campaign.",
      "cveBoundary": "behavioural",
      "threat": {
        "attacker": "user",
        "vector": "unsafe-default",
        "outcome": "exfiltration"
      },
      "evidence": [
        {
          "kind": "incident",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai"
        }
      ],
      "fix": {
        "summary": "The operator was the attacker, so victims depend on the model provider and the cloud provider detecting and cutting off the campaign.",
        "actions": [
          {
            "type": "reconfigure",
            "target": "chatbot-provider.misuseDetection",
            "to": "detects and cuts off accounts building credential-harvesting campaigns",
            "why": "Recommended: an AI coding chatbot helped plan, build and run the campaign in under six hours.",
            "owner": "model-provider"
          },
          {
            "type": "reconfigure",
            "target": "cloud-provider.abuseDetection",
            "to": "detects mass scanning from a compromised resource",
            "why": "Recommended: the campaign used a compromised cloud resource.",
            "owner": "infra-provider"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "An AI coding chatbot with preconfigured agent instructions",
          "any": false,
          "status": "confirmed",
          "source": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai"
        },
        "model": {
          "value": "any",
          "any": true,
          "status": "confirmed",
          "source": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai"
        },
        "goal": {
          "value": "Mass credential harvesting",
          "stated": true,
          "status": "confirmed",
          "source": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai"
        },
        "tools": {
          "value": "Compromised cloud resource, automated scanning and credential-harvesting workflows",
          "status": "confirmed",
          "source": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai"
        },
        "approval": {
          "value": "The campaign ran through preconfigured instructions without reported human review of each action",
          "mode": "auto-approve",
          "status": "detected",
          "source": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai"
        },
        "inputControl": "operator",
        "agentAction": "The agent-enabled workflow scans for and harvests third-party credentials.",
        "harm": "credential-theft",
        "divergence": "decomposed-misuse",
        "reach": {
          "value": "Third-party credentials and a compromised cloud resource",
          "kinds": [
            "cloud-credentials",
            "api-keys",
            "network"
          ],
          "status": "confirmed",
          "source": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai"
        },
        "condition": {
          "value": "When preconfigured agent instructions were used as the campaign's operational playbook",
          "status": "confirmed",
          "source": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai"
        },
        "scale": {
          "statement": "Thousands of third-party credentials were compromised",
          "unit": "accounts",
          "value": null,
          "source": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai"
        }
      },
      "occurrence": {
        "basis": "real-use",
        "reportedBy": "vendor"
      },
      "exploitation": {
        "status": "none-known",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai",
            "type": "research",
            "note": "GTIG reported a real threat campaign."
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "claims": [],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "reported-only",
        "missing": [
          "vulnerable components are not confirmed obtainable",
          "trigger not published"
        ]
      },
      "severityBasis": "harm-reach"
    }
  }
}
