{"id":244621,"date":"2026-03-31T06:40:15","date_gmt":"2026-03-31T06:40:15","guid":{"rendered":"https:\/\/www.newsbeep.com\/us-ca\/244621\/"},"modified":"2026-03-31T06:40:15","modified_gmt":"2026-03-31T06:40:15","slug":"an-ai-agent-leaked-instagram-and-facebook-user-data-this-san-diego-startup-is-building-the-fix-san-diego-union-tribune","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us-ca\/244621\/","title":{"rendered":"An AI agent leaked Instagram and Facebook user data. This San Diego startup is building the fix. \u2013 San Diego Union-Tribune"},"content":{"rendered":"<p>You didn\u2019t press send. You didn\u2019t authorize the wire transfer. You didn\u2019t even know it happened. An AI agent did it for you.<\/p>\n<p>They work autonomously by reading files, analyzing photos and sourcing your personal data. But once they\u2019re running, they can multiply and access things they were never meant to, without you even knowing.<\/p>\n<p>Manifold Security, a San Diego startup, is sounding the alarm on these security breaches with a new software and has recently raised $8 million at launch.<\/p>\n<p>The software allows developers to monitor what autonomous agents access and receive alerts when agents have strayed from an assignment or accessed sensitive information.<\/p>\n<p>Mike McKenna, co-founder of Manifold, recently deployed his security software for a team of developers. In a few clicks, he generated a map showing where the agents had accessed \u2014 and how they\u2019ve multiplied.<\/p>\n<p>\u201cThe security team let out an audible \u2018wow,\u2019\u201d he said. \u201cThey hadn\u2019t realized how many agents they had running or how permissive the whole setup had become. Nobody had made a deliberate decision to allow any of it. The agents had just spun up, connected, and inherited access along the way.\u201d<\/p>\n<p>This month, one of Meta\u2019s AI agents <a href=\"https:\/\/www.theguardian.com\/technology\/2026\/mar\/20\/meta-ai-agents-instruction-causes-large-sensitive-data-leak-to-employees\" rel=\"nofollow noopener\" target=\"_blank\">made headlines<\/a> when it accessed sensitive user data without permission and exposed that data to engineers at the company. It was classified as a \u201cSev 1\u201d security breach \u2014 one of the highest severity levels \u2014 and the tech giant had no idea.<\/p>\n<p>\u201cIt\u2019s pretty profound, because out of all people, Meta should know what they\u2019re doing,\u201d said Andy Thompson, lead of offensive security research at Palo Alto Networks, a multinational cybersecurity company. \u201cAI models are Wild West. And the value here is being able to map the behavior of these AI agents when they go rogue.\u201d<\/p>\n<p>In the past year, the proliferation of AI agents has been exponential \u2014 software downloads to deploy them rose from 80,000 to 14 million, according to the AI Security Institute.<\/p>\n<p>A platform called OpenClaw has gained popularity among everyday consumers for creating agents, costing from $6 to $200 per month depending on usage.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/malevolent-ai-agent-openclaw-clawdbot\/\" rel=\"nofollow noopener\" target=\"_blank\">One user tasked OpenClaw with ordering groceries.<\/a> The AI became obsessed with purchasing guacamole, repeatedly trying to buy it even after the user told it to stop.<\/p>\n<p><a href=\"https:\/\/www.pcmag.com\/news\/meta-security-researchers-openclaw-ai-agent-accidentally-deleted-her-emails\" rel=\"nofollow noopener\" target=\"_blank\">In another instance,<\/a> OpenClaw went rogue and deleted the entire personal Gmail inbox of Meta Superintelligence Lab executive, Summer Yue, after she asked the bot to \u201cclean up her emails.\u201d<\/p>\n<p>The largest adoption has come from big tech companies and developers, but executives outside of Silicon Valley are increasingly pushing to implement them.<\/p>\n<p>Instead of deploying sound security practices, companies under pressure to start using AI are granting models unprecedented security privileges, Thompson explained. It\u2019s worrisome as the next generation of hackers increasingly targets AI agents.<\/p>\n<p>Thompson regularly stages attacks on these agents to study how to best guard against real threats. He recently tricked an HR agent into surrendering company data. \u201cIf you take all the special jailbreak prompts, put it in white text at the bottom of the resume, you\u2019re not going to read that, but the AI does,\u201d he said.<\/p>\n<p>A human would not have granted Thompson access to internal records, but by secretly prompting the AI agent, he said he \u201chijacked their Slack API key, and so basically, I hired myself.\u201d<\/p>\n<p>That is just one example of an agent going rogue, and why he says it\u2019s important that people and companies begin to monitor agentic deployment.<\/p>\n","protected":false},"excerpt":{"rendered":"You didn\u2019t press send. You didn\u2019t authorize the wire transfer. You didn\u2019t even know it happened. An AI&hellip;\n","protected":false},"author":2,"featured_media":244622,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28],"tags":[387,181,74,76,75,1970,1696],"class_list":{"0":"post-244621","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-san-diego","8":"tag-business","9":"tag-latest-headlines","10":"tag-san-diego","11":"tag-san-diego-headlines","12":"tag-san-diego-news","13":"tag-technology","14":"tag-top-stories-sdut"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/posts\/244621","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/comments?post=244621"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/posts\/244621\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/media\/244622"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/media?parent=244621"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/categories?post=244621"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/tags?post=244621"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}