Systematic GitHub API queries are increasingly used for corporate reconnaissance prior to attacks, as threat actors abuse public APIs and leverage dormant ghost accounts to mimic legitimate usage patterns.
The JadePuffer attack demonstrates that although the AI agent acted technically autonomously, a human orchestrated infrastructure, target selection, and access credentials.
Three chained bugs in Microsoft 365 Copilot allowed attackers to exfiltrate corporate data via a legitimate microsoft.com link, as traditional anti-phishing filters did not block legitimate sources.