Agents have repeatedly been tricked into revealing credentials, and patching one attack path has still left others open.