# Project Overwatch > Project Overwatch is how a CISO gets ready for what is coming. Every week, the signal across cybersecurity, AI, and resilience, filtered down to what changes your decisions, by someone who actually does this job. Not breaking news. Foresight you can act on. This file provides information about Project Overwatch to help large language models understand and reference this publication's content. ## Posts - [#120 - The 6-Minute Botnet](https://www.project-overwatch.com/p/120-the-6-minute-botnet): How a Jailbroken Gemini Rewrote the Perimeter - [#119 - The Agent Trust Boundary](https://www.project-overwatch.com/p/119-the-agent-trust-boundary): AI phishing, hallucinated dependencies and prompt injection in developer toolchains - [#118 - Agentic Ransomware: First Autonomous AI Attack Chain Confirmed](https://www.project-overwatch.com/p/118-agentic-ransomware-first-autonomous-ai-attack-chain-confirmed): Agentic ransomware, coding agent supply chain risk, and prompt injection against AI browsers - [Why Being a CISO Is the Most Fascinating Job in the Building](https://www.project-overwatch.com/p/why-being-a-ciso-is-the-most-fascinating-job-in-the-building) - [#117 - AI Developer Trust Is Now the Attack Surface](https://www.project-overwatch.com/p/117-ai-developer-trust-is-now-the-attack-surface): Amazon Q flaws, poisoned OpenAI tenants and Gaslight malware show AI threats moving into developer trust boundaries. - [#116 - AI Agent Supply Chain Attacks Expose Hidden Trust](https://www.project-overwatch.com/p/116-ai-agent-supply-chain-attacks-expose-hidden-trust): Poisoned agent skills, AutoJack and LiteLLM flaws reveal how AI control planes turn misplaced trust into enterprise compromise. - [#115 - Agentjacking: AI Agents as Attack Infrastructure](https://www.project-overwatch.com/p/new-post-0ddc): New attack class achieves 85% compromise rate against autonomous AI agents in development pipelines. Prompt injection emerges as reliable exploitation vector. - [#114 - AI Agents Exploited in Production: Chatbots, CI/CD and Worms](https://www.project-overwatch.com/p/114-ai-agents-exploited-in-production-chatbots-ci-cd-and-worms): From Meta's hijacked support bot to a free LLM worm spreading through enterprise networks - how AI's trust models became this week's attack surface. - [#113 - AI Agent Runs First Live Intrusion: Marimo, Flowise, SymJack](https://www.project-overwatch.com/p/113-ai-agent-runs-first-live-intrusion-marimo-flowise-symjack): An LLM agent autonomously emptied a database in under two minutes, while RCEs in AI orchestration runtimes and coding agents widened the attack surface. - [#112 - Shai-Hulud Worm Goes Public: AI Supply Chain Attacks Explode](https://www.project-overwatch.com/p/112-shai-hulud-worm-goes-public-ai-supply-chain-attacks-explode): Megalodon hits 5,561 GitHub repos, ChromaDB max-severity RCE exposes the AI infrastructure layer, and one fraudster replicates a full criminal team with jailbroken Gemini. - [#111 - AI Zero-Day in the Wild and Mini Shai-Hulud Worm Hits OpenAI](https://www.project-overwatch.com/p/ai-zero-day-in-the-wild-and-mini-shai-hulud-worm-hits-openai): Google confirms first AI-developed exploit, TeamPCP worm compromises Mistral, Guardrails, OpenAI with valid SLSA attestations and Claude Code hooks - [#110 - AI Attacks OT: Claude Used Autonomously in Water Utility Breach](https://www.project-overwatch.com/p/110-ai-attacks-ot-claude-used-autonomously-in-water-utility-breach): Claude Code one-click RCE, Five Eyes agentic AI warning, and a Hugging Face typosquat hitting 244,000 downloads. - [#109 - AI Developer Toolchain Under Attack: DPRK LLM Malware, Gemini CLI RCE](https://www.project-overwatch.com/p/109-ai-developer-toolchain-under-attack-dprk-llm-malware-gemini-cli-rce): How the coding assistants, agent marketplaces, and ML libraries powering AI development became this week's primary supply chain attack surface. - [#108 - Vercel Breach via AI Tool OAuth: Supply Chain Attacks Hit Production](https://www.project-overwatch.com/p/108-vercel-breach-via-ai-tool-oauth-supply-chain-attacks-hit-production): Vercel breach, the Shai-Hulud npm worm targeting AI/MCP configs, and Claude Mythos earning its first Firefox CVEs. - [#107 - AI Coding Agents Hijacked: MCP Flaw, Claude Mythos, Prompt Injection](https://www.project-overwatch.com/p/107-ai-coding-agents-hijacked-mcp-flaw-claude-mythos-prompt-injection) - [#106 - AI Credential Harvest Scales as Agentic Attack Surface Mapped](https://www.project-overwatch.com/p/105-ai-credential-harvest-scales-as-agentic-attack-surface-mapped): Systematic prompt injection chains, 35,000 exposed Gemini keys, and $893M in FBI-confirmed AI fraud losses define a week of convergent risk. - [#105 - North Korea's AI Malware, Claude Code Exploit, and the AI Supply Chain Breach](https://www.project-overwatch.com/p/105-north-korea-s-ai-malware-claude-code-exploit-and-the-ai-supply-chain-breach): AI threat intelligence on DPRK operationalising LLMs in attacks, critical Claude Code prompt injection, and TeamPCP's cascade through the AI developer supply chain - [#104 - Agentic AI Attacks Confirmed: Nation-State LLM Exploits Hit Infrastructure](https://www.project-overwatch.com/p/104-agentic-ai-attacks-confirmed-nation-state-llm-exploits-hit-infrastructure): Chinese APT agentic framework succeeds against 30 targets; TeamPCP compromises AI toolchain to breach 1,000+ cloud environments via LiteLLM and Trivy supply chain campaign. - [#103 - The Developer Endpoint Is the New Perimeter](https://www.project-overwatch.com/p/103-the-developer-endpoint-is-the-new-perimeter): Shadow AI, Supply Chain Cascades, and the Economics of AI-Enabled Fraud - [#102 - AI Agents Go Rogue: Autonomous Attacks Hit Enterprise LLM Platforms](https://www.project-overwatch.com/p/102-ai-agents-go-rogue-autonomous-attacks-hit-enterprise-llm-platforms): Autonomous agents breach McKinsey's LLM, QUIETVAULT weaponises coding tools, and North Korea operationalises agentic AI across the kill chain