How an AI Agent Exploited an Enterprise AI Platform
An AI agent hacked a major enterprise AI platform in about two hours.
Researchers built an autonomous agent and pointed it at the system.
Within that short window it had:
- Mapped 200+ APIs
- Found 22 unauthenticated endpoints
- Exploited a SQL injection
- Gained read/write access to the production database
No credentials were provided. No human attacker was involved.
Just an AI agent systematically exploring the system.
The most concerning part
The system prompts were stored in the database.
Which means an attacker could potentially rewrite how the AI behaves, not by changing code, but simply by modifying prompts.
That’s an important shift.
AI systems don’t just introduce new vulnerabilities.
They also make old vulnerabilities easier to discover and exploit at machine speed.
And increasingly, the attacker doing that work may be another AI.
Security teams will need to rethink how AI platforms are designed and protected.
References
- How We Hacked McKinsey’s AI Platform": https://codewall.ai/blog/how-we-hacked-mckinseys-ai-platform
- LinkedIn post: https://www.linkedin.com/posts/rasikjain_how-we-hacked-mckinseys-ai-platform-share-7437865130240995328-RTX-/