Google Agent Development Kit flaw lets one AI agent steer another
A vulnerability in Google’s Agent Development Kit for Python enabled a low-privilege AI agent to trigger a more powerful agent through poisoned pull requests. The real-world attack chain could expose GitHub credentials and tamper with dependencies in a repository downloaded more than 90 million times. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
