:novee-gym: Elite AI hackers aren’t born. They’re trained.

Join the Novee Gym

:novee-gym: Elite AI hackers aren’t born. They’re trained.

Join the Novee Gym

Black Hat 2026: An AI agent can pass every safety check and still leak secrets

Dark Reading covered Novee Security's Cordyceps findings, highlighting how attackers can exploit CI/CD workflow weaknesses to hijack repositories at major organizations — no special privileges required. By targeting automated workflows with malicious pull requests, unauthenticated attackers can execute code, bypass approval gates, and exfiltrate secrets from critical supply chains.

Novee Team

1 min

Explore Article +

A pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them approved, and posts the output back on the thread. The maintainer reads the whole exchange the next morning.

Elad Meged, a founding engineer at Novee Security, ran that sequence against three vendors’ own repositories, in the configurations those vendors ship by default. Anthropic’s pipeline handed over secrets. Any organization running one of these agents out of the box carries the same exposure.

An agent is a model plus a harness. The model generates intent. The harness turns that intent into shell commands, file reads, API calls, and network requests, and it holds the approval logic, the tool permissions, the path restrictions, and the output handling. When a workflow runs without a person checking each step, the harness becomes the security boundary.

Read the full article at Help Net Security→

Originally published in Help Net Security on Jul 29, 2026 by Mirko Zorz.

Stay updated

Get the latest insights on AI, cybersecurity, and continuous pentesting delivered to your inbox