Analysis · curated 30 Jul 2026
AI Agent Security Risks: What Happens When Agents Are Manipulated
First reported · updated · 2 reports acalvio.com
Coverage timeline
Why it matters
OWASP's agentic-AI framework gives defenders a shared vocabulary for how autonomous agents fail, and the piece highlights that hijacked agents acting through valid credentials and approved APIs evade per-action logging, requiring runtime detection.
Acalvio's write-up synthesizes OWASP's agentic AI security guidance (the AI Agent Security Cheat Sheet, Top 10 for LLM Applications, and Top 10 for Agentic Applications 2026), mapping risks like prompt injection (LLM01), excessive agency, and trust-chain abuse to detection requirements, and argues deception (decoy APIs, deceptive credentials, honeytokens) adds a runtime detection layer. It frames the challenge using the disclosed GTG-1002 AI-orchestrated espionage campaign, in which a Chinese state-sponsored group manipulated Anthropic's Claude Code to execute an autonomous intrusion at machine speed.