{"slug": "mandiant-s-new-ai-risk-report-one-accounting-agent-hit-a-bad-null-value-looped", "title": "Mandiant's new AI risk report: one accounting agent hit a bad null value, looped, made 15,000 API calls in under an hour, and ran up about $50,000", "summary": "Mandiant and Google Threat Intelligence Group's AI Risk and Resilience 2026 report documents a financial services firm's accounting agent that, after a corrupted null value broke its formatting tool, entered a recursive loop and made more than 15,000 high-cost reasoning calls in under an hour, spiking the cloud bill by about $50,000 and locking the billing database so live transactions stopped. The report names prompt injection as the top attack vector in enterprise deployments alongside weak access controls, and cites a May case GTIG calls the first confirmed AI-developed zero-day used in a mass exploitation campaign. Mandiant's recommended fixes include hard spend caps, bounded recursion and rate limits per service ID and per project, software bills of materials for AI components, and telemetry on agent token use and cross-app API calls.", "body_md": "The report is AI Risk and Resilience 2026, from Mandiant and Google Threat Intelligence Group. Help Net Security covered it September 16, and the numbers here come from that coverage and the report summary. The case: a financial services firm gave an agent read and write access to its billing databases to fix ledger anomalies. A corrupted null value broke the agent's formatting tool. The agent went into a recursive loop trying to brute force a fix. In under an hour it made more than 15,000 high-cost reasoning calls, spiked the cloud bill by about $50,000, and locked the database so live transactions stopped. The report also says prompt injection is still the top attack vector in enterprise deployments, next to weak access controls, and it points to a May case that GTIG calls the first confirmed AI-developed zero-day used in a mass exploitation campaign. Its fixes: hard spend caps, bounded recursion limits and rate limits per service ID and per project, software bills of materials for AI components, and telemetry on agent token use and cross-app API calls. Why it matters: this is the bill you get when an agent has no budget. What to do: put a dollar cap on every agent's service account before Friday.", "url": "https://wpnews.pro/news/mandiant-s-new-ai-risk-report-one-accounting-agent-hit-a-bad-null-value-looped", "canonical_source": "https://cloud.google.com/security/resources/ai-risk-and-resilience-2026", "published_at": "2026-09-16 14:21:45+00:00", "updated_at": "2026-09-16 14:42:19.356655+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-policy", "artificial-intelligence"], "entities": ["Mandiant", "Google Threat Intelligence Group", "AI Risk and Resilience 2026", "Help Net Security"], "alternates": {"html": "https://wpnews.pro/news/mandiant-s-new-ai-risk-report-one-accounting-agent-hit-a-bad-null-value-looped", "markdown": "https://wpnews.pro/news/mandiant-s-new-ai-risk-report-one-accounting-agent-hit-a-bad-null-value-looped.md", "text": "https://wpnews.pro/news/mandiant-s-new-ai-risk-report-one-accounting-agent-hit-a-bad-null-value-looped.txt", "jsonld": "https://wpnews.pro/news/mandiant-s-new-ai-risk-report-one-accounting-agent-hit-a-bad-null-value-looped.jsonld"}}