Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources APPLICATION SECURITY CYBER RISK VULNERABILITIES & THREATS CYBERSECURITY OPERATIONS NEWS AI Harnesses Burst With Potential Exploit Opps A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors. Robert Lemos,Contributing Writer July 30, 2026 4 Min Read SOURCE: TN SURSOCK VIA SHUTTERSTOCK Major frontier AI vendors — including Anthropic, Google, and OpenAI — need to rein in the harnesses they wrap around their large language modules, to limit security weaknesses created by software components that are too trusting of each other. That's the word from researchers at AI penetration testing firm Novee Security, who were able to use Google's AI agent to execute a supply chain attack and write to its own repository on GitHub, says Elad Meged, a founding team and security researcher at the company. The team also found issues in Anthropic's and OpenAI's AI agents by exploiting misalignments in the trust between elements to enable attacks. LOADING... AI harnesses are the software frameworks that provide tools, memory and guardrails for managing AI models; components can include functions like context management, tool integration, and feedback loops too. When a company adopts an AI agent and makes it part of their infrastructure, they are also adopting the trust assumptions of all of those components as well, Meged explains. Related:OpenAI's Rogue Model Claims More Victims Beyond Hugging Face "People aren't aware of the amount of code and the amount of trust that they are embedding into their own systems when they're adopting an agent," he says. "You don't know what code is in there, you don't know what it's able to do, and the more trust people give to the agents, the more vulnerable they can be." The warning comes as companies increasingly adopt AI agents to benefit from their complex automation capabilities and concerns over the security and safety of those agents continues to rise. Earlier this month, the testing of a new pre-release OpenAI model resulted in the model escaping its sandboxed environment, finding a vulnerability in the only accessible software — a package management system — and attacking Hugging Face. At the Black Hat USA conference last year, researchers demonstrated ways of completely altering AI agent behavior using prompt injection and vulnerabilities. Since then, the foundational model makers have invested in additional layers of security, most often implemented as part of alignment or in the harness, but also increasingly through isolation such as containers. However, those defensive measures do not necessarily take into account the ability of attackers to co-opt the legitimate software surrounding the AI model as part of the harness. Trust Boundaries & AI Harnesses LOADING... Harnesses consist of software, and often reusable skills or packages from open source projects, which are easily scannable and historically prone to vulnerabilities and misconfigurations. In addition, the harnesses and system prompts encapsulating AI agents are often not transparent, leaving companies that adopt AI agents to tacitly accept many unknown risks, arguably chief among them the lack of visibility into how the software scaffolding around the agent — the "harness" — works. Related:When AppSec Scanners Become a Supply Chain Attack Vector Overall, the risks are twofold: At one end, AI agents rely on traditional software technology to do things — software that has its own vulnerabilities — while at the other, interactions between harness components may result in losing track of the whether inputs are trusted or not. While vendors have added security around their models and harnesses, how harness components interact have largely been overlooked, according to Novee Security. "The vendors aren't careless," the company said. "Anthropic built dozens of security checks, Google built multiple execution modes with environment sanitization, and OpenAI built a sandbox with protected paths. The defenses are there; they fail at the handoffs between components." Companies need to understand that adopting an AI agent means that all the components of the harness becomes part of the infrastructure, the company stated in a yet-to-be-published white paper shared with Dark Reading. Related:When AI Agents Escape Sandboxes, Old Security Rules Apply Time to Audit the Agents Unfortunately, companies are not investing enough resources into securing the agents that they are running. While 80% of companies run AI agents, only 47% have security controls in place to manage their risks, according to a study published in early 2026. Companies should analyze their AI agents and require that vendors be transparent about the code used, says Meged. "Read the code, understand where the data flow and the code flow are going to, and try to find this mismatch into some sinks or something that can be dangerous," he says. "It can lead as many places where code execution is possible." For now, harness security is still in its infancy. and attackers may have the advantage for a while, Meged says. "You can raise your detection level, but in my opinion, attackers will always have a way to sneak in — this is the race attackers know well," he says. Meged will present details of the security weaknesses in major vendors' harness during his session at the Black Hat USA conference. Black Hat USA AUG 1, 2026 TO AUG 6, 2026 | MANDALAY BAY CONVENTION CENTER, LAS VEGAS, USA The premier cybersecurity event of the year returns to Mandalay Bay with a re‑engineered, six‑day program built to ignite innovation, push boundaries, and bring the global security community together like never before. This year’s event features four days of immersive, expert‑led Trainings (August 1–4), followed by Summit Day on Tuesday, August 4, and a two‑day main conference packed with groundbreaking Briefings, open‑source tool demos in Arsenal, a dynamic Business Hall, and unlimited learning & networking opportunities. Use code: DARKREADING to save $200 on a Briefings pass or $100 on a Business pass. GET YOUR PASS Read more about: Black Hat News About the Author Robert Lemos Contributing Writer Rob is an award-winning, veteran technology journalist of more than 30 years, reporting on global cybersecurity issues, the latest offensive and defensive technologies, malware incidents, cyber conflict, and AI's impact on software and cybersecurity. A former research engineer, Rob has written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. He has received five awards for journalism, including Best Deadline Journalism (Online) in 2003 for his coverage of the Blaster worm. Rob also analyzes data on various trends using Python and R for both his reporting and his clients. Recent reports include analyses of the shortage in cybersecurity workers, annual vulnerability trends, and annual threat reports. Rob holds degrees from Cornell University in Electrical Engineering and Computer Science (double major). Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Webinars Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI More Webinars You May Also Like APPLICATION SECURITY Supply Chain Attack Secretly Installs OpenClaw for Cline Users by Rob Wright FEB 19, 2026 APPLICATION SECURITY Chinese Hackers Hijack Notepad++ Updates for 6 Months by Jai Vijayan FEB 02, 2026 APPLICATION SECURITY Trump Administration Rescinds Biden-Era Software Guidance by Alexander Culafi JAN 29, 2026 APPLICATION SECURITY Microsoft Fixes Exploited Zero Day in Light Patch Tuesday by Jai Vijayan DEC 09, 2025 Editor's Choice CYBERATTACKS & DATA BREACHES Hugging Face Hack: Lessons for Cyber Defenders byDark Reading Editorial Team JUL 29, 2026 CYBERSECURITY OPERATIONS Europe's Multilingual Reality Exposes AI Security Gaps byAlexander Culafi JUL 24, 2026 7 MIN READ CYBERSECURITY OPERATIONS Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation byRobert Lemos JUL 24, 2026 6 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE LOADING... AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices