The part that worries me most isnt AI-generated malware- its AI agents getting their own cloud creds. we're already seeing OIDC trust policies being setup for bedrock and copilot agents with the same 'make it work and move on' attitude that created the static credential problem in CI/CD pipelines. the EC breach happened because a static API key sat in a pipeline untouched for months. Now imagine that same negligence but with the autonomous agents that can act on those creds without human intervention.
trustfixsec•58m ago