Vulnerability  ·  2026-09-19

Mandiant/GTIG 2026 AI Risk and Resilience Report — self-propagating worm via hijacked AI coding assistant, agentic runaway cost incidents, and AI-driven supply-chain compromise (UNC6780)

VulnerabilityHigh impactGlobal
Mandiant/Google Threat Intelligence Group's September 2026 AI Risk and Resilience report documents a shift from human-guided prompting of AI chatbots to autonomous agentic attack orchestration. It cites concrete 2026 incidents including a hijacked coding assistant spreading a self-propagating worm across ~100 repositories, a compromised CI/CD credential used to co-debug exfiltration tools with an LLM in real time, and threat actor UNC6780 systematically weaponizing AI coding assistants and LLM security scanners via prompt injection to steal AI credentials and data.
This is direct evidence that AI coding agents and CI/CD-integrated LLM tooling are now an active, exploited attack surface — not a theoretical risk. Worm-like propagation through hijacked coding assistants and prompt-injection-driven manipulation of AI security scanners represent a novel agent-execution attack class with real-world incident data, directly matching the highest-priority category the CVE seed misses entirely.
Multiple documented patterns: (1) a hijacked coding assistant used as a vector to spread a self-propagating worm across roughly 100 code repositories; (2) a compromised CI/CD credential enabled an attacker to co-debug exfiltration tooling with an LLM in real time; (3) threat actor UNC6780 (TeamPCP) used more than half a dozen methods to exploit AI tools and open-source ecosystems, including prompt injection to manipulate AI coding assistants and LLM security scanners, to steal AI-service credentials and proprietary AI data; (4) backdoored OpenClaw AI agent skill packages distributed droppers/infostealers/RATs disguised as automation packages.
AI coding assistants/agents (unspecified vendors), CI/CD pipelines integrating LLM tooling, agentic automation platforms, OpenClaw AI agent skills ecosystem
Treat AI coding assistants and agent skill/plugin ecosystems as a first-class supply-chain attack surface: vet and scan agent skills/extensions before installation, enforce short-lived scoped credentials for CI/CD-integrated agents, monitor for anomalous cross-repository propagation patterns, and apply prompt-injection defenses to any AI security scanner or coding assistant with write access to source control.
Mandiant AI Risk and Resilience Report 2026SecurityWeek — In Other News: Mandiant's 2026 AI risk report
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →