🔥 24×7 Proxy Interview Support · Job Support · Profile Engineering | USA • Canada • UK • Europe • Australia

ProxyTech ResearchEngineering Research Archive

Autonomous AI Agent Security

An independent engineering-research archive. We take live evidence — academic papers on arXiv, primary security disclosures, and threat intelligence — and work out what it means for teams building and operating production AI agents. Not summaries. Not news. A running investigation into the security boundaries that autonomous, tool-using models break, and the architectures that hold.

Active cluster

Autonomous AI Agent Security

Publications

11

Evidence reviewed

September 2026

Evidence base

Academic researchPrimary disclosures · Threat intel
Featured research

The incident that made this concrete

AI Agent Security · Flagship incident researchAnatomy of an AI-Orchestrated Intrusion: A Technical Reconstruction of GTG-1002The flagship. In November 2025 Anthropic disclosed a campaign in which an agent ran the majority of an intrusion lifecycle at machine speed. We reconstruct the architecture, isolate the boundary that failed, and build the counterfactual secure deployment.INCIDENTPRIMARY SOURCEANALYSISOPEN QUESTION22 min
Active research cluster · latest

All publications in this cluster

11 publications

Research areas

What we investigate

Research questions

Questions driving the cluster

Open questionsOPEN QUESTION
  • Can any defense drive indirect prompt-injection success low enough for high-privilege production agents?
  • How much autonomous offensive capability is real versus an artifact of information handed to the benchmark?
  • What is the right identity model for an agent that acts for a user but is not the user?
  • Is behavioral alignment ever a sufficient substitute for architectural containment?
  • How do you detect an agent that is doing exactly what it was told — by an attacker?
Incident research

Real-world incidents we analyze

DisclosedIncident / disclosurePrimary sourceAnalyzed in
Nov 2025GTG-1002 — AI-orchestrated cyber espionageAnthropicThe GTG-1002 Incident
Jun 2025EchoLeak — zero-click M365 Copilot injectionAim Security; Microsoft (MSRC)Prompt Injection
Oct 2025CamoLeak — Copilot source-code exfiltrationLegit Security; GitHubNetwork Egress
Aug 2025CVE-2025-53773 — Copilot RCE via prompt injectionJ. Rehberger (Embrace The Red); MicrosoftAI Coding Agents
Aug 2025Cursor CurXecute / MCPoisonAim Security (CurXecute); Check Point Research (MCPoison)AI Coding Agents
Sep 2025postmark-mcp — malicious MCP serverKoi Security; SnykMCP Security
Jul 2025mcp-remote RCE (CVE-2025-6514)JFrog Security ResearchMCP Security
Engineering evidence

Recent papers we are following

From the ProxyTech blog

Accessible lead-ins

ProxyTech Research is an independent engineering-analysis project. We reference public academic papers and primary security disclosures; we do not claim peer review, journal publication, arXiv affiliation, or academic positions, and we do not represent the cited authors or vendors.