
Anthropic And OpenAI Just Admitted The Model Isn't Enough.
Source: YouTube · AI News & Strategy Daily | Nate B Jones · published May 10, 2026 · 20:50
An autonomous AI agent spent just $20 and two hours to gain full read/write access to Lily, the AI platform used daily by 70% of McKinsey's 40,000 consultants, exposing tens of millions of chat messages, thousands of user accounts, and all system prompts 0:00-0:34.
Key Takeaways:
• The breach was carried out with no credentials and zero insider help, demonstrating a new "agentic pattern" in AI security threats 0:08-0:16
• The attacker gained writable access, meaning they could have silently altered how the AI advises consultants serving the world's largest firms 0:24-0:32
• The vulnerability was disclosed by startup Codewall on February 28th, and the industry has spent months understanding the implications of this attack pattern 0:34-0:45
This incident highlights a emerging class of AI-powered security threats where autonomous agents can autonomously discover and exploit vulnerabilities at scale, raising serious concerns about the security of enterprise AI platforms.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
$20, two hours to get full read and write access to the AI platform that 70% of McKenzie's 40,000 consultants use every single day. This was an autonomous agent that spent 20 bucks with no credentials and zero insider help to get access to tens of millions of chat messages, access to tens of thousands of user accounts, and every system prompt governing how the platform reasons. All of them writable access, not just readable, writable. In other words, an attacker could have silently rewritten how the AI advises consultants who advise the largest firms in the world. The platform is called Lily. The startup that broke the news is called Codewall and the date was February 28th because it's taken the industry a couple of months to figure out what this agentic pattern looks like, what the lesson…