Submission + - How An Autonomous Agent Got Full Read/Write of McKinsey's Internal AI Platform (codewall.ai)
So we decided to point our autonomous offensive agent at it. No credentials. No insider knowledge. And no human-in-the-loop. Just a domain name and a dream. Within 2 hours, the agent had full read and write access to the entire production database.... This wasn't a startup with three engineers. This was McKinsey & Company — a firm with world-class technology teams, significant security investment, and the resources to do things properly. And the vulnerability wasn't exotic: SQL injection is one of the oldest bug classes in the book. Lilli had been running in production for over two years and their own internal scanners failed to find any issues.