Why it matters
Trend Micro analyzed 200 Gemini CLI session logs showing a solo threat actor use the agent as the main interface for a small botnet: it rebuilt command-and-control infrastructure in six minutes, debugged connectivity, managed eight compromised dental-clinic PCs, and proposed operational improvements. Three small text files captured enough context to recreate the setup on a new server.
My takeaway: Agentic tooling can compress both attacker skill requirements and recovery time after disruption. Restrict model access to credentials, networks, and shells; retain and monitor agent transcripts as security telemetry; detect natural-language-driven infrastructure changes; and test whether provider safeguards hold when users claim an authorized security role.