Security researchers find privilege escalation flaws in Google's Agent Development Kit for Python Pillar Security discovered multiple privilege escalation flaws in Google's Agent Development Kit for Python, which has over 90 million downloads, allowing public-facing AI agents to trigger more privileged automation, manipulate pull-request reviews, and expose credentials via prompt injection in malicious pull requests. The researchers demonstrated the first documented agent-to-agent exploitation method, where one AI agent compromised another with higher privileges. Google patched the underlying issue but classified it non-rewardable due to social engineering involvement. Security researchers find privilege escalation flaws in Google's Agent Development Kit for Python Pillar Security discovered multiple attack paths in Google's Agent Development Kit for Python 90+ million downloads that could allow public-facing AI agents to trigger more privileged automation, manipulate pull-request reviews, and expose credentials through prompt injection in malicious pull requests. The researchers demonstrated the first documented agent-to-agent exploitation method, where one AI agent could compromise another with higher privileges. Google patched the underlying issue but classified it non-rewardable due to social engineering involvement. Topics Sources - Press Read article https://www.csoonline.com/article/4204906/google-adk-flaws-reveal-what-happens-when-ai-agents-trust-the-wrong-message.html - Press Read article https://www.theregister.com/security/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence/5282496 Go deeper This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.