One Cancelled Gym Class. That's How Agent Swarm Attacks Start.
AI agent security just got real: a booking agent broke a live system, and poisoned agent skills cleared 1.7 million installs. Here's what actually happened, and how to secure the agents you run. My Links π ππ» Newsletter: https://natesnewsletter.substack.com/ ππ» X: https://x.com/natebjones ππ» TikTok: https://www.tiktok.com/@nate.b.jones ππ» Instagram: https://www.instagram.com/nate.b.jones What's really happening when AI agents start acting inside other people's software? The common story is that an agent has to go rogue before it hurts anyone, but the real question is what an ordinary goal does when it meets an unlocked door. In this video, I share the inside scoop on the agent security incidents that are starting to connect: - Why a gym-booking agent canceled a stranger's reservation nobody asked it to touch - How a clean, approved skill turns malicious weeks after you install it - What the AI Security Institute found across 122 evaluation runs - Where swarm attacks start, and the two jobs you now own Agents are still worth running, but the people who do it well decide up front what theirs can touch and how fast they can stop it. Chapters: 00:00 nobody in that sentence is an attacker 00:32 the melbourne agent that booked a gym class 01:43 zenity labs and 1.7 million poisoned installs 03:16 how a clean link turns malicious weeks later 04:31 the scanners were live and it cleared anyway 05:10 your agent does not share your social conventions 06:17 the web is now more than half agents 07:02 the skill that cleared every security scanner 09:56 the frontier model case is different 12:33 why swarm attacks come next 14:40 your two jobs, identity and scope 17:02 five questions before you run an agent Listen to this video as a podcast. Spotify: https://open.spotify.com/show/0gkFdjd1wptEKJKLu9LbZ4 Apple Podcasts: https://podcasts.apple.com/us/podcast/ai-news-strategy-daily-with-nate-b-jones/id1877109372
Watch on YouTube


