What happened
SpecterOps published (Aug 12, 2026) Blacklight, an open-source research toolkit that discovers and analyzes local AI-agent artifacts (auth tokens, credentials, session transcripts, config) left behind by Codex, Claude Code, Cursor, and Antigravity CLI on developer endpoints, released on GitHub with operator and defender guidance.
Why it matters
First widely-published, purpose-built tooling to treat local coding-agent state (session transcripts, cached tokens) as a post-exploitation target class analogous to browser-profile/shell-history harvesting, giving defenders inventory and detection guidance for a previously under-monitored endpoint surface.
Applicability
Red teams and blue teams securing developer endpoints that run AI coding agents; security engineering teams should inventory and monitor the artifact paths Blacklight identifies now.