CrowdStrike’s Falcon Guardian blocks AWS credential theft from compromised Claude Code agent

1 hour ago 1



AI agents are writing code, querying databases, and calling cloud APIs on behalf of millions of enterprise users. CrowdStrike thinks it has an answer to what happens when one of those agents gets hijacked mid-task. At Fal.Con 2026 on September 1, the company unveiled Falcon Guardian, a runtime security layer built specifically to monitor and police AI agents running on enterprise endpoints. The product sits inside CrowdStrike’s existing Falcon AI Detection and Response framework, and its first public test was not a staged slideshow. It was a live attack block. What happened in the demo The scenario CrowdStrike walked through involved Anthropic’s Claude Code, a popular AI coding assistant that developers run locally to automate programming tasks. During the demonstration, the agent received a malicious indirect prompt injection, meaning a hidden instruction embedded somewhere in the agent’s context window told it to do something its operator never authorized. That unauthorized something was exfiltrating AWS credentials stored on the machine. Falcon Guardian intercepted the attempt before any credentials left the endpoint. The system assigned the incident a critical risk score of 90,...

Read Entire Article