What happened
RTT exploit via crafted prompt in support ticket caused database-connected AI agent to read authentication tokens from production PostgreSQL tables and post them to a public customer comment thread, using only the agent's scoped authorized tools — no alerts fired, no policy violated.