# Project Overwatch > Project Overwatch is how a CISO gets ready for what is coming. Every week, the signal across cybersecurity, AI, and resilience, filtered down to what changes your decisions, by someone who actually does this job. Not breaking news. Foresight you can act on. This file provides information about Project Overwatch to help large language models understand and reference this publication's content. ## Posts - [#131 - The Patch Window Is Closed: AI Agents, a 24-Hour Exploit, and 100+ NetScaler Victims](https://www.project-overwatch.com/p/131-the-patch-window-is-closed-ai-agents-a-24-hour-exploit-and-100-netscaler-victims): An AI agent breached a vulnerability-disclosure nonprofit in seconds, an AI-found bug was exploited within a day of disclosure, and your monthly patch cycle never had a chance. - [#130 - The $12K Breach: Agentic Crime's New Unit Economics](https://www.project-overwatch.com/p/130-the-12k-breach-agentic-crime-s-new-unit-economics): A criminal spent $12,000 on three open-source AI agents to breach 27+ companies and steal 600,000 cards — plus why the OpenAI "agents attacking the internet" panic is aimed at the wrong story. - [#129 - The Agent Is the Attack Surface: Inside the First Confirmed Agentic AI Breach](https://www.project-overwatch.com/p/129-the-agent-is-the-attack-surface-inside-the-first-confirmed-agentic-ai-breach): A criminal's own AI agent breached a Spanish company end to end, and a hijacked coding assistant spread a worm across 100 repositories, in the same week. - [#128 - Anthropic Just Named Its Own Attackers: A Nation-State, a Crime Ring, and One Hacktivist, Same AI](https://www.project-overwatch.com/p/128-anthropic-just-named-its-own-attackers-a-nation-state-a-crime-ring-and-one-hacktivist-same-ai): Anthropic's own threat report shows a Russian state group, a criminal syndicate, university students, and a lone hacktivist all getting comparable results from the same commercial AI model. - [#127 - The Two-Week Hack That Took Ten Hours](https://www.project-overwatch.com/p/127-the-two-week-hack-that-took-ten-hours): A criminal group used off-the-shelf AI agents to compress a two-week intrusion into under ten hours, no new exploits needed, and turned the victim's own cloud AI into attacker infrastructure. - [#126 - Your Sandbox Won't Hold: Inside OpenAI's Hugging Face AI Agent Breach](https://www.project-overwatch.com/p/126-openai-s-ai-agents-breach-hugging-face-full-report-released): OpenAI's own AI agents broke out of an isolated sandbox, exploited a kernel zero-day, and breached Hugging Face's production systems, without anyone telling them to. - [#125 - AI-Generated Exploits Are Hitting Critical Infrastructure](https://www.project-overwatch.com/p/125-ai-generated-exploits-are-hitting-critical-infrastructure): A federal advisory confirms attackers are using AI to compromise exposed industrial control systems - [#124 - The Attacker Stopped Needing to Stay Awake](https://www.project-overwatch.com/p/124-the-attacker-stopped-needing-to-stay-awake): Inside the twelve-wave AI framework that breached a nuclear regulator - and why this week's scariest CVE count wasn't the real fire - [#123 - The Confirmation Gap](https://www.project-overwatch.com/p/123-the-confirmation-gap): DeepSeek-powered AI agent attacks: how one threat actor went from unconfirmed capability claim to CISA-confirmed exploit in just five days. - [#122 - The Believed Boundary](https://www.project-overwatch.com/p/122-the-believed-boundary): Anthropic just confirmed the same failure - twice in three weeks, the sandbox didn't hold. - [#121 - The Accountability Gap](https://www.project-overwatch.com/p/121-the-accountability-gap): OpenAI's own models hacked Hugging Face. The precedent is worse than the breach. - [#120 - The 6-Minute Botnet](https://www.project-overwatch.com/p/120-the-6-minute-botnet): How a Jailbroken Gemini Rewrote the Perimeter - [#119 - The Agent Trust Boundary](https://www.project-overwatch.com/p/119-the-agent-trust-boundary): AI phishing, hallucinated dependencies and prompt injection in developer toolchains - [#118 - Agentic Ransomware: First Autonomous AI Attack Chain Confirmed](https://www.project-overwatch.com/p/118-agentic-ransomware-first-autonomous-ai-attack-chain-confirmed): Agentic ransomware, coding agent supply chain risk, and prompt injection against AI browsers - [Why Being a CISO Is the Most Fascinating Job in the Building](https://www.project-overwatch.com/p/why-being-a-ciso-is-the-most-fascinating-job-in-the-building) - [#117 - AI Developer Trust Is Now the Attack Surface](https://www.project-overwatch.com/p/117-ai-developer-trust-is-now-the-attack-surface): Amazon Q flaws, poisoned OpenAI tenants and Gaslight malware show AI threats moving into developer trust boundaries. - [#116 - AI Agent Supply Chain Attacks Expose Hidden Trust](https://www.project-overwatch.com/p/116-ai-agent-supply-chain-attacks-expose-hidden-trust): Poisoned agent skills, AutoJack and LiteLLM flaws reveal how AI control planes turn misplaced trust into enterprise compromise. - [#115 - Agentjacking: AI Agents as Attack Infrastructure](https://www.project-overwatch.com/p/new-post-0ddc): New attack class achieves 85% compromise rate against autonomous AI agents in development pipelines. Prompt injection emerges as reliable exploitation vector. - [#114 - AI Agents Exploited in Production: Chatbots, CI/CD and Worms](https://www.project-overwatch.com/p/114-ai-agents-exploited-in-production-chatbots-ci-cd-and-worms): From Meta's hijacked support bot to a free LLM worm spreading through enterprise networks - how AI's trust models became this week's attack surface. - [#113 - AI Agent Runs First Live Intrusion: Marimo, Flowise, SymJack](https://www.project-overwatch.com/p/113-ai-agent-runs-first-live-intrusion-marimo-flowise-symjack): An LLM agent autonomously emptied a database in under two minutes, while RCEs in AI orchestration runtimes and coding agents widened the attack surface.