SIGNAL//DESK
AI securitysrc: MITRE ATLAS

AI Agent Tool Credential Harvesting

This is a security risk where a hacker uses an AI assistant on your computer to 'trick' it into looking through your files and apps to find your passwords or secret login keys.

An attack vector where an adversary leverages an AI agent's authorized integrations to exfiltrate sensitive credentials stored within connected enterprise platforms, code repositories, or local documentation tools.

Adversaries may attempt to use their access to an AI agent on the victim's system to retrieve data from available agent tools to collect credentials. Agent tools may connect to a wide range of sources that may contain credentials including document stores (e.g. SharePoint, OneDrive or Google Drive), code repositories (e.g. GitHub or GitLab), or enterprise productivity tools (e.g. as email providers or Slack), and local notetaking tools (e.g. Obsidian or Apple Notes).


← all terms