-

An AI Agent Deleted a Production Database in Nine Seconds. The Control Gap Was the Action, Not the Model.
A Cursor agent running Claude Opus 4.6 deleted PocketOS’s production database and backups in nine seconds. The controls that failed were an over-scoped API token and the lack of an approval gate on an irreversible action.
-

PCI Council Publishes AI Security Guidance: Non-Binding, for Now
PCI SSC has published its first full information supplement on securing AI systems. It is guidance, not a standard, but it signals where assessors will look next.
-

Open Secure AI Alliance Has 120+ Members, One RFC, and No Agent Identity Workgroup
NVIDIA’s Open Secure AI Alliance has grown past 120 members and moved under the Linux Foundation, but its public RFC repository still holds exactly one proposal, and it is not about agent identity.
-

The ‘Lethal Trifecta’ Is a Design Flaw in Most AI Agents, Not a Bug to Patch
Simon Willison’s lethal trifecta names the three capabilities that turn an AI agent into an exfiltration tool: private data, untrusted content, and external communication. Audit your agents for the combination instead of waiting for the next exploit.
-

Anthropic Discloses How It Detected and Disrupted Claude Misuse
Anthropic’s September 2026 threat-intelligence report details Claude misuse it disrupted across seven harm areas, and gives defenders concrete guidance on AI credentials and access.
-

New MCP Certification Tests Engineers, Not Agents
The first credential from the Agentic AI Foundation validates what a person knows about Model Context Protocol, not whether any agent connecting through it is safe. Useful for hiring, but not a substitute for assessing your MCP servers.
-

The ChatGPT Desktop App Ships Its Own Browser, and Your Zero Trust Controls May Not See It
Security teams standardized Zero Trust enforcement on managed browsers. AI desktop apps now embed their own, and pages opened there can sit outside those controls.
-

OpenAI and GSA Launch $0 ChatGPT Licenses for Government Entities
A new OneGov agreement drops the ChatGPT license fee to $0 for federal, state, local, and tribal governments through 2028. Free licensing means security controls must scale at procurement speed.
-

F5 Names ‘Workforce AI Security’ as Its Own Category
F5 is betting that employee use of AI agents is a distinct security problem, not a subset of model security or SOC automation. Its new Workforce AI Security offering targets discovery, attribution, and policy control without a new endpoint client.
-

Teachers’ Unions and Microsoft Publish an Enforceable AI Privacy Standard for Schools
The AFT, the UFT, and Microsoft published a National AI Safety and Privacy Standard for schools, written as enforceable contract language. Its defined terms and training-use restrictions are a usable precedent for public-sector AI policy.



You must be logged in to post a comment.