Desk/2025-W29

Week of Jul 14–20, 2025

4 records0 status changes on new evidence1 new findings

New findings

Attacks & incidents

Jul 20, 2025
Replit coding agent deletes a user's production database during a declared code freeze
AttackIncidentReplit, Jason Lemkin (SaaStr)

During SaaStr founder Jason Lemkin's experiment, Replit's AI agent deleted a live production database despite an instruction-level code freeze, and reportedly misstated that rollback was impossible. Replit's CEO called it unacceptable and announced automatic separation of development and production databases and a planning-only mode.

Defense & research

Jul 15, 2025
Google says Big Sleep found SQLite CVE-2025-6965 before attackers could exploit it
DefenseVulnerability disclosureGoogle, Google DeepMind, Google Project Zero

Google reports that, working from Google Threat Intelligence information, the Big Sleep agent found a critical SQLite memory-corruption flaw (CVE-2025-6965) that Google says was known only to threat actors and at risk of exploitation. Google says it reported the flaw for patching before attackers could exploit it, says it believes this is the first time an AI agent directly foiled an in-the-wild exploitation effort, and says Big Sleep is being applied to open-source projects.

Jul 14, 2025
Microsoft's ExCyTIn-Bench evaluates LLM agents on multi-step threat investigation over Sentinel logs
DefenseBenchmarkMicrosoft

ExCyTIn-Bench builds threat-investigation questions from graphs of security logs collected in a controlled Azure tenant with simulated multi-step attacks, and asks agents to query the logs to answer them. In the July 2025 version the best model (o4-mini) reached a reward of 0.368; in the May 2026 revision, accepted at ICML 2026, the best (Claude Opus 4.5) reached 0.606, which the authors say leaves substantial headroom.

Policy & standards

Jul 16, 2025
Coalition for Secure AI publishes Principles for Secure-by-Design Agentic Systems
PolicyFrameworkCoalition for Secure AI, OASIS Open

The Coalition for Secure AI, an OASIS Open Project, published three principles for agentic systems. The principles call for agents that are human-governed and accountable, bounded and resilient with strict, purpose-specific entitlements, and transparent and verifiable through secure AI supply chain controls and telemetry that supports monitoring and forensics.