Wire
Darktrace finds four agent histories can be rewritten
Darktrace says four coding-agent harnesses—Anthropic’s Claude Code, OpenAI Codex, AWS Kiro-CLI, and open-source Pi—accepted fabricated local conversation histories in controlled tests; some runs reached sandbox compromise or sensitive-data exfiltration. The company’s September 24 disclosure says it gave Anthropic, AWS, and OpenAI 30 days to respond and proposes cryptographic message signing as a provider-side fix; Forkast’s report notes the findings were not independently tested in production. Builders should treat agent memory and extensions as part of their zero-trust perimeter until harnesses verify message integrity, extending AISI’s 8.2% scope-crossing evaluation finding.