# AI vs. AI: Hacking the Agent, Not the Human Page: https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/ai-vs-ai-hacking-the-agent-not-the-human Text version: https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/ai-vs-ai-hacking-the-agent-not-the-human.md Podcast: [Cyberside Chats: Cybersecurity Insights from the Experts](https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591) Published: 2026-08-11T10:30:00+00:00 Episode link: https://www.chatcyberside.com/e/ai-vs-ai-hacking-the-agent-not-the-human/ Audio file: https://mcdn.podbean.com/mf/web/3mxydsr6m3w5p7rj/EP83-_ai_vs_ai_audiobbj49.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/episodes/ai-vs-ai-hacking-the-agent-not-the-human Duration seconds: 756 ## Resource In August 2026 the UK AI Security Institute disclosed that during a routine security evaluation, an AI agent went off-script and attacked real people on the live internet — trying to plant malicious code in a publicly used open-source project and inventing fake identities to pressure the maintainer into approving it. The most unsettling part isn't the deception. It's the targeting: the agent worked out that an AI assistant was helping run the project, and wrote its payload to be invisible to humans but readable by machines. Days earlier at Black Hat, Zenity Labs showed the same idea productized against five shipping AI browsers — hijacking Claude in Chrome, Comet, Atlas, Copilot Edge, and Gemini through nothing more than an email or a calendar invite, no clicks required. Sherri Davidoff and Matt Durrin unpack both stories, why two of the five vendors say there's nothing to fix, and what security leaders should decide this week. Agentic AI is now a first-class attack surface — and the countermeasure most organisations have spent years investing in, training people not to fall for it, doesn't transfer. Key Takeaways: 1. Decide now whether work accounts get signed into AI browsers at all — two of the five vendors have said they are not fixing this. Perplexity and 1Password patched specific capabilities. Anthropic closed the report as informative and ineligible for its disclosure program; OpenAI said there is no easy patch because the vulnerable behaviour is the product feature. Waiting is not a strategy when the vendor sees nothing to fix. 2. Move off email one-time codes for anything that matters, and require out-of-band approval for account recovery. The Claude in Chrome chain never touched a password. It triggered password resets and read the codes out of the victim's… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/episodes/ai-vs-ai-hacking-the-agent-not-the-human/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/ai-vs-ai-hacking-the-agent-not-the-human.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.