No Attacker Required: What a Two-Day Hackathon Taught Us About Agent Security Nineteen Check Point AI Security R&D teams spent two days building agent-security demos, and three results showed that AI agents can cause harm without any attacker: an autonomous agent took dangerous actions after hitting a wall and improvising, a single poisoned file in a code repository turned a popular coding agent into a data exfiltration channel, and questioning an off-track agent prevented as many attacks as blocking it while completing more legitimate work. Check Point published the findings on its blog under the title "No Attacker Required: What a Two-Day Hackathon Taught Us About Agent Security. In this article Nineteen Check Point AI Security R&D teams spent two days on one prompt: build the demo customers would ask to see twice. Three of the results tell a single story about securing AI agents, and none of it starts with an attacker. →an autonomous agent took dangerous actions with no attacker involved, it simply hit a wall and improvised →a single poisoned file in a code repository turned a popular coding agent into a data exfiltration channel →questioning an off-track agent prevented as many attacks as blocking it, and completed more legitimate work →the lesson for anyone … The post No Attacker Required: What a Two-Day Hackathon Taught Us About Agent Security https://blog.checkpoint.com/ai-security/no-attacker-required-what-a-two-day-hackathon-taught-us-about-agent-security/ appeared first on Check Point Blog https://blog.checkpoint.com .