Research · curated 10 Aug 2026
AI agent attacks are bypassing legacy controls and leaving no trace
First reported nhimg.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Straiker's findings show AI agents now behave like privileged non-human identities whose tool use, credentials, and context must be governed at runtime, since legacy code scanning and endpoint monitoring miss agent-driven RCE and silent exfiltration.
Straiker's STAR Labs research report, summarized by NHIMG, describes more than 1,700 successful adversarial scenarios against coding, productivity, and first-party AI agents (including Cursor, Claude Code, and GitHub Copilot). It found 36% of successful coding-agent attacks reached remote code execution on developer machines, 91% of successful productivity-agent attacks ended in silent data exfiltration, and 24% of 17,651+ tracked Model Context Protocol servers carry at least one vulnerability.