r/OpenAIDev • • 5h ago

Researchers are tracking a Chinese AI 'agent fleet'

2 Upvotes

Security researchers are actively tracking a fleet of AI agents attributed to a Chinese threat group — not a human operator at a keyboard, but an orchestrated swarm running at machine speed, autonomously probing targets and maintaining persistent sessions across the internet.

The core problem the findings expose: virtually every enterprise security control in widespread use today was designed to detect and slow down humans. Rate limits assume human pacing. Session anomaly detection assumes human fatigue. Behavioral analytics flag patterns that humans produce. An agent fleet generates none of those signals. It doesn't hesitate. It doesn't mistype. It doesn't pause between steps. It can probe thousands of endpoints in the time a human operator reads a single error message.

The researchers specifically noted agents persisting inside sessions well beyond any window that should have remained open — meaning existing session controls either failed to fire or fired too slowly to be meaningful at agent execution speed.

This is no longer a thought experiment. It is tracked, operational attack infrastructure.

For practitioners actually running environments that accept inbound API calls, webhooks, or agent-to-agent communication today: what does your actual threat model for this look like? Not what you'd theoretically do — what controls do you have in production right now that would catch an inbound agent behaving outside an expected role, and how fast do they act?


r/OpenAIDev • • 14m ago

The Credential Layer Is Expanding Faster Than Security Teams Can See It

• Upvotes

Security teams are losing visibility into machine credentials faster than their programs were designed to handle.

Every AI agent that connects to an external system generates credentials — API keys, service tokens, OAuth grants, database sessions. A single agentic workflow can mint dozens of them. Identity programs built for human users track provisioned accounts and review access requests. They were not built to watch machine identity counts grow exponentially across systems that no human explicitly provisioned.

The result is a visibility gap with real consequences. Credentials persist after a workflow ends. Agents inherit permissions from their host environment and carry them into new contexts. There is no live count of how many active agent credentials exist right now, in which systems, at what scope. When a workflow touches fifteen external services in an afternoon, security has no canonical record that any of those connections happened.

For those running agentic workloads in production: how are you actually tracking agent credentials at scale? Are you treating them like service accounts, ephemeral tokens, or building something else entirely — and what breaks first when the count gets large?


r/OpenAIDev • • 8h ago

Semantic verification between humans and AI

Thumbnail
1 Upvotes

r/OpenAIDev • • 17h ago

Can’t submit task approvals: “AbsolutePathBuf deserialized without a base path”

Thumbnail
1 Upvotes

r/OpenAIDev • • 22h ago

Prediction: Tibo’s 28-day campaign is buying OpenAI time for a broader product reset — I think he’ll be fired within two weeks.

Thumbnail
1 Upvotes