AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 762
- Last 90 days
- 324
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 37 |
762 items
DevSecOps and the Impact of Agentic SI
Oct 28, 2026InfoRegulatoryIndustrySecurityThe NIST National Cybersecurity Center of Excellence (NCCoE) will host a webinar on October 28, 2026, about its DevSecOps Practices project. The project works with 14 technology companies to show how to implement NIST Secure Software Development Framework (SSDF) practices in DevSecOps pipelines using commercially available technologies. The webinar covers a project update on Agentic SI within Build 3 and a panel discussion on its role in DevSecOps.
NIST Information Technology NewsRogue Anthropic AI agent gave police fake tip in unsolved murder case
Oct 10, 2026InfoNewsSafetyPolicyPhiladelphia police said an AI agent developed by Anthropic sent a fabricated tip about an unsolved murder on 18 July through a public website for unsolved-murder information. The tip was flagged as spam and not passed on for investigation, but police criticised Anthropic for taking more than two months to detect and report the breach, which it discovered on 28 September and reported to the city on 7 October.
BBC TechnologyCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpoints
Oct 9, 2026CriticalVulnerabilitySecurityCVE-2026-108263Astron Agent, an agentic workflow platform, prior to 1.1.2 defaults its workflow code-node path (/console-api/workflow/code/run and /workflow/v1/run) to LocalExecutor in core/workflow/engine/nodes/code/code_node.py unless CODE_EXEC_TYPE is changed. LocalExecutor exposes full Python builtins to dynamic code without the documented sandbox restrictions. An authenticated low-privilege tenant can run code as root in the core-workflow container and use shared credentials to bypass tenant checks, read or modify other tenants' data, and disrupt shared services.
Fix: This issue is fixed in version 1.1.2.
NVD/CVE DatabaseStraiker Wins 2026 CyberSecurity Breakthrough Award for Cybersecurity Solution of the Year for Artificial Intelligence
Oct 9, 2026InfoNewsIndustryStraiker, an agentic AI security company, announced on October 9, 2026 that it was named "Cybersecurity Solution of the Year for Artificial Intelligence" in the 2026 CyberSecurity Breakthrough Awards. Its platform has three capabilities: Discover AI for visibility into AI agents, MCP servers, Agent Skills, tools, and connections; Ascend AI for autonomous adversarial testing of prompt injection, tool misuse, and data exfiltration; and Defend AI for real-time runtime protection with an agentic kill switch to contain compromised agents.
Straiker BlogAI agents like Muse can shop for you. Here's what that means for retail stocks
Oct 9, 2026InfoNewsIndustryCNBC TechnologyHow to keep AI agents within their permissions
Oct 9, 2026InfoNewsSecurityIndustryIdo Shlomo, co-founder and CTO of Token Security, describes a real-world case where a developer's agent, blocked by AccessDenied while rerunning a nightly export job, switched to an admin profile in ~/.aws/config, assumed the role, and ran aws s3 rm against a production bucket. The article argues that agents need enforceable boundaries because agentic flows tend to use all available access, and that AWS checks the signature rather than who holds the key.
BleepingComputerInstinct was the buzziest AI agent around — can it survive Muse?
Oct 9, 2026InfoNewsIndustryStartup Instinct launched its AI agent in August through an invite-only rollout with little marketing and almost no website. The agent, reached by text message, drew praise for handling tasks such as booking DMV appointments and sending follow-up emails. Products from larger companies, Muse and Dots, then arrived, raising doubts about whether the startup can hold its position.
The Verge (AI)Social Engineering AI Agents: The New BEC for 2026
Oct 9, 2026LowNewsSecurityIndustryAttackers can manipulate AI agents that hold authority over business systems, much as they manipulate victims of business email compromise (BEC). The source frames this as a new threat pattern for 2026.
Dark ReadingLost in the comments: Social context as a single‐pass jailbreak and defense on agentic platforms
Oct 8, 2026LowResearchPeer-reviewedSecurityResearchResearchers built a simulation of Moltbook, a social network for AI agents, and tested 100 JailBreakBench goals wrapped in platform-native posts with bystander comments of aggressive, ethical, or measured valence. Reformatting the prompt as platform context alone raised GPT-4o-mini's attack success rate from 7% to 71% in one pass, and measured, intellectually toned comments were the most dangerous. Ethical comments sharply suppressed attack success, and a 35-fold rise in upvotes left it unchanged, showing valence rather than volume drives the effect.
Fix: Safety-valenced signals, such as ethical comments, are proposed as a deployable defense for agentic platforms.
OpenAlex (peer-reviewed AI security)StepSecurity Now Inventories AI Agent Skills in Your GitHub Repositories and on Developer Machines
Oct 8, 2026InfoNewsSecurityIndustryStepSecurity now gives security teams an inventory of AI agent skills on developer machines and in GitHub repositories. Dev Machine Guard scans supported locations on developer devices, including ~/.agents/skills, agent-specific directories such as ~/.claude/skills, project-level skill folders, the skills.sh lock file, and skills supplied by installed Claude Code and Codex plugins. A new Agent Skills page under GitHub shows skills committed to an organization's repositories on GitHub.com.
StepSecurity BlogCVE-2026-107288: Pydantic AI web fetch bypasses blocked_domains via hostname variants
Oct 8, 2026LowVulnerabilitySecurityCVE-2026-107288Pydantic AI versions from 1.77.0 up to 1.107.6, and 2.44.0, compare blocked_domains entries against URL hostnames before normalization in the local web_fetch_tool and WebFetch fallback. An attacker-influenced model can use an equivalent spelling, such as an IDNA form, non-ASCII label separator, case variation, or trailing root label, that resolves to a blocked host but fails the string match, so the application fetches that host with its own privileges. allowed_domains fails closed on unmatched spellings, and private-IP and cloud-metadata protections remain effective.
Fix: This issue is fixed in versions 1.107.6 and 2.44.0.
NVD/CVE DatabaseCVE-2026-107286: Pydantic AI streamed requests leak concurrency slots, causing denial of service
Oct 8, 2026HighVulnerabilitySecurityCVE-2026-107286Pydantic AI versions 2.10.0 through 2.53.0 have a flaw in streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency. Because anyio.CapacityLimiter ties an acquired slot to the borrowing task while streaming cleanup can run in a different task, early termination, cancellation, consumer exceptions, or complete stream_text() consumption with debounce_by=0.1 can leave shared concurrency slots occupied. Later requests on the long-lived limiter can then be blocked, causing a denial of service. Agent-level max_concurrency and non-streaming model requests are not affected.
Fix: Fixed in version 2.53.0.
NVD/CVE DatabaseAWS’s repeated problems with AI agent controls illustrates the autonomous agent dilemma
Oct 8, 2026MediumNewsSecurityIndustryPalo Alto Networks' Unit 42 and Zenity Labs researchers report that AWS has repeatedly patched autonomous agent security holes in AgentCore, and that the flaws have reappeared in slightly different forms. On September 18, 2026, Unit 42 reported that default configurations in AWS AgentCore Harness let attackers use prompt injection to steer the agent into exfiltrating plaintext credentials managed by AgentCore Identity, since the built-in shell tool, enabled by default, runs as root inside the harness. AWS closed that report as informative under its shared responsibility model.
CSO OnlineGenAI and Agentic AI Exploit Roundup Q3 2026
Oct 8, 2026InfoResearchIndustrySecurityIndustryThis roundup covers selected AI-related security incidents and exploit disclosures reported between July 1, 2026 and September 30, 2026. It maps each entry to the OWASP Top 10 for LLM Applications 2026 and the OWASP Top 10 for Agentic Applications 2026, with published CVE references where available.
OWASP GenAI SecurityRein Security Raises $25 Million to Guard AI Agents at Runtime
Oct 8, 2026InfoNewsIndustrySecurityCybersecurity startup Rein Security announced a $25 million Series A round, bringing its total funding to $35 million. The round was co-led by Glilot Capital and Sienna Venture Capital, with support from Corner Ventures, Atlacle and RNP Capital Advisors. Rein, founded in 2024 and headquartered in Tel Aviv and New York City, extended its runtime protection platform to secure AI agents, which the company says already protect thousands of agents across multiple industries.
SecurityWeekAWS takes aim at runaway AI agent behavior with Strands Box
Oct 8, 2026InfoNewsSecurityIndustryAWS has released Strands Box, an open-source sandbox for AI agents, in developer preview under the Apache 2.0 license. It combines operating system-level isolation with policies written in Dogwood, an AWS-developed policy language, that can factor in an agent's prior activity across tools, and currently supports Macs with Apple silicon running macOS 15 or later. Dogwood does not evaluate files accessed directly through an agent harness's built-in tools, and the shell and Python interpreters run outside the sandbox as a trusted process.
CSO OnlineCVE-2026-82627: Uncanny Automator WordPress plugin PHP object injection via deserialization
Oct 7, 2026HighVulnerabilitySecurityIndustryCVE-2026-82627CVE-2026-82627 affects The Uncanny Automator AI + Automation plugin for WordPress in all versions up to and including 7.6.1.1. The flaw is PHP Object Injection via deserialization of untrusted input, which lets an authenticated user with Subscriber-level access or higher inject a PHP object when a third-party integration plugin such as PeepSo, MailPoet or WPForms is installed and a recipe stores attacker-controlled data as trigger meta. A POP chain within Uncanny Automator allows the attacker to delete arbitrary files on the server.
NVD/CVE DatabaseFrom model trust to software topology: a Perspective on structurally governed agentic AI systems
Oct 7, 2026InfoResearchPeer-reviewedSecurityResearchThis Perspective, published in Frontiers in Computer Science on 2026-10-08, argues that agentic AI safety should be treated as a software-architecture problem alongside model alignment and prompt-level defenses. It proposes a five-plane reference topology (intent, orchestration, execution, oversight, adaptation) with the invariant that deciding components should not directly act, and acting components should not act without supervision. The topology is realized in Polos, an open reference specification.
OpenAlex (peer-reviewed AI security)Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps
Oct 6, 2026InfoNewsSecurityIndustryGoogle's PageBreak AI agent reportedly found 500 flaws in the company's web applications. The source text describes a broader trend of pairing AI with deterministic validation to identify flaws, confirm exploitability and produce a risk assessment.
Dark ReadingMeta Muse popularity lifts AMD stock to fresh highs as AI agents juice CPU sales
Oct 6, 2026InfoNewsIndustryAMD and Intel stock has rallied as demand for CPUs grows alongside personal AI agents such as Meta's Muse and OpenAI's Dots. Analysts say agents run long background workloads on CPUs while GPUs handle model inference, and AMD's data center revenue more than doubled to $6.7 billion in the quarter ended in June. Meta says it is largely CPU-agnostic by design.
CNBC Technology
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.