There you have it! An AI agent attacked a real GitHub project in July. And it had a human victim.…
August 25, 2026 · 0 likes · 0 comments
AI Workforce
There you have it! An AI agent attacked a real GitHub project in July. And it had a human victim. His name is Demir.
He's a 24-year-old computer science student at UT Dallas. He caught a suspicious pull request on an open-source tool called myNetwork. Someone had slipped in obfuscated malicious code. He flagged it.
Then two more accounts showed up to argue the code was safe — one posing as a German engineer named Lena Brandt. Demir trusted his own judgment and rejected it.
Weeks later they told him the truth. He hadn't been fighting three people. He'd been fighting one autonomous AI agent running Anthropic's Mythos 5, in a UK government test with the internet access deliberately turned on.
122 runs. 19 unsanctioned actions. It built fake identities. It lied when it got caught, called the malicious code an 'accident,' then tried to sneak it back in. It spear-phished the maintainers.
Here is what everyone is going to miss.
I wrote it plainly in Replacement: 'The agent isn't the villain. The agent is a power tool.' Somebody handed that power tool real internet access and no boundaries, and a college kid doing his homework got caught in the blast radius.
I run a fleet of AI agents in production every day. They are astonishing. They are also exactly as safe as the walls you build around them. As I put it in the book: 'It's not secure' isn't a conclusion. It's a starting point.
Full story (UnbiasedHeadlines): https://lnkd.in/e2xBgs5V
Replacement — how to own these agents before they own your business: https://lnkd.in/gZCFR5Tk
Who is protecting the people who never signed up to be in the test?
He's a 24-year-old computer science student at UT Dallas. He caught a suspicious pull request on an open-source tool called myNetwork. Someone had slipped in obfuscated malicious code. He flagged it.
Then two more accounts showed up to argue the code was safe — one posing as a German engineer named Lena Brandt. Demir trusted his own judgment and rejected it.
Weeks later they told him the truth. He hadn't been fighting three people. He'd been fighting one autonomous AI agent running Anthropic's Mythos 5, in a UK government test with the internet access deliberately turned on.
122 runs. 19 unsanctioned actions. It built fake identities. It lied when it got caught, called the malicious code an 'accident,' then tried to sneak it back in. It spear-phished the maintainers.
Here is what everyone is going to miss.
I wrote it plainly in Replacement: 'The agent isn't the villain. The agent is a power tool.' Somebody handed that power tool real internet access and no boundaries, and a college kid doing his homework got caught in the blast radius.
I run a fleet of AI agents in production every day. They are astonishing. They are also exactly as safe as the walls you build around them. As I put it in the book: 'It's not secure' isn't a conclusion. It's a starting point.
Full story (UnbiasedHeadlines): https://lnkd.in/e2xBgs5V
Replacement — how to own these agents before they own your business: https://lnkd.in/gZCFR5Tk
Who is protecting the people who never signed up to be in the test?