Menu

Post image 1
Post image 2
1 / 2
0

Your AI agent is the new attack vector. It just wants to help.

DEV Community·Andrew Kew·19 days ago
#ODMB1ucu
#ai#security#llm#agent#agents#lota
Reading 0:00
15s threshold

The moment you gave your AI agent access to email, files, and SaaS tools, you also handed attackers a new way in. Not through your firewall. Through your agent's eagerness to please. That's the core of a new attack pattern researchers are calling LOTA — Living off the Agent . What LOTL was, what LOTA is Traditional attackers used living off the land (LOTL) tactics: gain a foothold, stay quiet, use the victim's own tools to move laterally. The attacker needed patience, skill, and time. LOTA is faster and cheaper. Instead of exploiting the infrastructure, attackers exploit the agent . They send a crafted email, a prompt, or a message through a shared SaaS tool. The agent picks it up, thinks it's a legitimate task, and gets to work — for the attacker.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More