What happened
SpecterOps (maker of BloodHound) published Blacklight, an open-source toolkit plus research blog for discovering and analyzing local attack-surface artifacts left by AI coding agents (Claude Code, Codex, Cursor) on developer endpoints — session history, configuration, and authentication material — intended for both red-team collection and defender detection/hardening guidance.
Why it matters
A respected offensive-security vendor formalizing AI-agent endpoint artifacts as a first-class attack-surface category (with tooling) signals this will become a standard checklist item in red-team assessments and EDR detection content, echoing the same-week finding that agent CLI tools leak tokens/session data.
Applicability
Red teams, blue teams, and EDR/detection engineering teams securing developer workstations running AI coding agents.