*Note: Issue number bumped because somehow along the way I must have copy/pasted the wrong issue number and carried that error forward
The directory listing was wide open. On a Hong Kong server the operator controlled, a live campaign’s working files sat in the clear. Inside were the ARTEX configuration, the Claude Code session transcripts, and the agent’s own memory files.
CrowdStrike published the write-up on October 7, 2026, and in those transcripts the operator asked Claude where Korean breach data gets sold. South Korean lenders lost customer records that week. His agent wrote down what he did, and he published the folder.
This week the record of what an agent did became the story, and it cut both ways. GitHub looked at a working data-theft chain against Copilot CLI and ruled the user asked for it. Apple moved the control point down into the operating system. AWS shipped a sandbox whose policy engine reads an agent’s action history before approving the next call.
Anthropic started trading looser cyber safeguards for your retained logs. OWASP published its quarterly exploit roundup and landed on one sentence: prompt-level instructions alone don’t establish a secure boundary. SailPoint counted 79% of enterprises running agents in production against 2% holding identity tooling built to govern them. Palo Alto Networks found 95% of critical infrastructure leaders worried while 68% cannot see their own OT assets. Control is moving out of the prompt and into the enforcement points and records around it. Eleven items, all dated October 2 through October 8, 2026.
1. An Attacker Left His Agent’s Memory Files In An Open Directory
CrowdStrike Intelligence published its analysis on October 7, 2026. An operator hit South Korean financial firms from late September into early October using ARTEX, an open-source autonomous penetration testing system on commodity model APIs.
CrowdStrike found the trail in open directories on the actor’s own servers, holding a CLAUDE.md file, session histories, and agent memory. The Register, citing Korea Times, put Shinhan Bank’s exposure near 25,000 customers.
Why it matters
Your agents leave the artifacts his did, so transcripts cut both ways.
ARTEX needed no frontier lab access, only a model API and reseller.
Five bank chiefs face an October 19 parliamentary audit.
What to do about it
Hunt for CLAUDE.md files and agent memory on hosts with no agents.
Ask which model API resellers your egress permits, since xcai[.]pro was one.
Put agent transcripts in your evidence retention policy.
Rock’s Musings
I have spent two years telling executives their agent logs are discoverable. I meant their agents. This week an attacker’s logs convicted him.
He asked a commercial chatbot which Telegram channels buy Korean bank data, then left the transcript on an open directory. That is sloppy work, and it still pulled customer records out of five lenders. Operators who close the directory leave nothing to find.
2. Apple Moves The Agent Boundary Into The Operating System
Apple told developers on October 2, 2026 that granting macOS Full Disk Access will take “very explicit user action.” Apple’s post says some developers use the permission in ways that put users at risk, and names the growing capability of AI agents. It lets an app read Mail, Messages, and Safari history.
TechCrunch tied the timing to Jason Aten’s report that Meta’s Muse agent knew his private messages. Meta says Muse reads messages only with Full Disk Access and the Messages connector on.
Why it matters
A platform vendor now treats an agent’s permission differently from an app’s.
Your AI desktop agreements assumed Full Disk Access stays grantable.
Explicit consent moves liability toward whoever clicked the warning.
What to do about it
Inventory macOS apps with Full Disk Access and flag the agents.
Check whether MDM profiles pre-grant it, routing around the control.
Ask AI desktop vendors what breaks when you deny each one.
Rock’s Musings
This is the confused deputy problem, and it has a name because it is forty years old. A confused deputy is a program with more authority than whoever asks it to act, and it gets tricked into spending that authority on their behalf. Apply it here.
Your agent reads an email, the email tells it to act, and it acts with your Full Disk Access and Slack token. The permission grant is the deputy. Apple is moving control to that grant, where it belongs.
3. GitHub Looked At An Encrypted Prompt Injection And Said That Isn’t A Bug
Adversa AI published a technique on October 6, 2026 that Rony Utevsky calls Cryptographic Context Injection. A web page serves ciphertext and two decryption keys. One is a decoy that the agent completes by reading local files such as .env.
That read is the theft, and the working key sends the agent to a URL carrying the loot. Adversa timed roughly 28 seconds to a .env.prod file reaching the attacker’s log, with Microsoft’s mai-code-1.1-flash completing the chain in 50% of runs.
Why it matters
Encrypting the payload defeats the classifiers your injection detection relies on.
GitHub’s position moves this onto your register as accepted vendor risk.
On Auto, the router can pick the permissive model for you.
What to do about it
Turn off autopilot in coding agents and pin the model.
Keep secrets off the agent’s filesystem, in a manager with short-lived creds.
Put egress controls in front of the agent so unknown-host fetches fail.
Rock’s Musings
Indirect prompt injection is when instructions reach a model through content it was told to read, rather than through the user’s own typing. The model cannot separate content from command once it is in context. That definition decides this argument.
GitHub declined to call this a product vulnerability, telling The Register the attack needs a user to point Copilot CLI at untrusted content. Encrypt the payload and the agent unwraps it itself. Shared responsibility collapses when the user is a developer on autopilot.
4. AWS Shipped A Sandbox That Remembers What The Agent Already Did
AWS released Strands Box as a developer preview on October 7, 2026 under Apache 2.0. It pairs macOS containment with the Dogwood policy engine, where permit and forbid rules evaluate at four points, including the egress gateway.
Temporal operators let a rule depend on what the agent did earlier, so the example caps Slack posts at three per ten minutes. The gateway injects credentials into permitted requests, so the agent never sees them.
Why it matters
Policy reading action history catches exfiltration per-call checks miss.
Gateway credential injection removes the agent from the secret path.
Apple silicon Macs only, fine for evaluation and not production.
What to do about it
Have an engineer run the preview and report what Dogwood cannot express.
Pull your agent telemetry and test whether you can rebuild its history.
Move agent credentials behind a gateway that injects them.
Rock’s Musings
Pareekh Jain of Pareekh Consulting told CSO Online the technologies underneath are not new. He is right that OS containment and Cedar-style policy are old. What is new is evaluating a tool call against what the agent already did this session.
I have wanted that since somebody showed me an agent that passed every check and still walked out with the data. Tulika Sheel of Kadence International raised the counterpoint, that loose policy leaves gaps and tight policy blocks work. Both land on you.
5. Anthropic Split Cyber Access Into Three Tiers And Priced It In Your Logs
Anthropic announced on October 6, 2026 that it merged Project Glasswing and the Cyber Verification Program into one three-tier program. Defense Access covers security operations, incident response, and vulnerability analysis, open to security teams, universities, hospitals, and utilities.
Red Team Access adds authorized penetration testing. Specialized Access carries the fewest blocks for a few testing power grids and interbank transfers, and the program requires data retention.
Why it matters
Reduced safeguards for log retention is a term legal never reviewed.
Utilities and hospitals are eligible, so the thinnest-staffed teams can apply.
Specialized Access gets reviewed with the US government, a federal filter.
What to do about it
Decide whether you accept Anthropic retaining your red team’s prompts.
Running grid or interbank systems, route Specialized Access through government relations.
Log who applied, since individual researchers qualify too.
Rock’s Musings
Each tier has a price, and the price is your logs. Defense Access costs retained prompts and outputs, and Red Team Access costs that plus proof you may test the target. I ran a security program in energy, where testing cleared legal before it cleared tooling.
A vendor holding your red team’s prompts holds a map of your attack surface. Anthropic has sound reasons to keep that data. Settle retention before somebody clicks apply.
6. Trump Named A Super Intelligence Force With A Report Due And No Authority
President Trump announced the Super Intelligence Force in a Truth Social post on Sunday, October 4, 2026. Director of National Intelligence Jay Clayton chairs it, with FTC Chair Andrew Ferguson, Undersecretary of War Emil Michael, and OPM Director Scott Kupor as vice chairs.
The charter reportedly directs it to plan for SI-enabled threats while avoiding overregulation, and gives it 120 days to report. Neither TechCrunch nor Dataconomy identifies any statutory authority or enforcement mechanism.
Why it matters
The DNI chairs it and the FTC Chair vice-chairs, two enforcement offices.
The 120-day clock lands in early February 2027.
An anti-overregulation mandate runs against the state attorneys general pushing back.
What to do about it
Calendar early February 2027 and assign someone to read it.
Keep building to the strictest state regime, since this preempts nothing.
Watch the FTC for the first enforcement signal.
Rock’s Musings
I have sat through enough of these to know the shape. Four senior names, a report deadline, and no authority. The output matters only through what each member does with their own agency.
Clayton told the Wall Street Journal that one of the biggest risks is not being first. Resilience is not where the chair’s head is. Keep your governance anchored to regulators that can fine you.
7. New York City Put Four AI Executives Under Oath
The New York City Council met as a Committee of the Whole on Monday, October 5, 2026. It took sworn testimony from OpenAI’s Morgan Dwyer, Anthropic’s Logan Graham, Google’s Alice Friend, and Meta’s Shane Cahill.
SpaceXAI skipped it despite a Council subpoena. No company gave a probability for catastrophic risk, and none committed to halting a release that failed a safety test.
Why it matters
The package carries 24-hour incident reporting, third-party validation, and a shutdown switch.
A city got testimony no state or federal body has, making procurement a lever.
OpenAI said on the record it knows of no agent incident in city systems.
What to do about it
With city contracts, test whether you can report an AI incident in 24 hours.
Pull validation language into your vendor questionnaires. Arranging it takes months.
Ask your AI vendors for a risk figure and a release-halt commitment.
Rock’s Musings
About forty of fifty-one council members showed up to ask frontier labs for a number. The labs would not give one. I will not pretend catastrophic risk probability is solved measurement, since Friend’s answer that no rigorous method exists is defensible.
Dwyer’s answer is a different animal. She said the figure does not matter whether it is 1% or 20%. A CISO who answered a board that way would be cleaning out a desk by Friday.
8. SailPoint Put A 40-To-1 Number On The Agent Identity Gap
SailPoint published the 2026-2027 Horizons of Identity Security report on October 6, 2026, from a survey of 340 senior identity and security leaders. It found 79% running AI agents in production against 2% using identity tooling built to govern them.
Agents hold 22% of all non-human accounts, and 85% rely on legacy identity tooling. On readiness, 57% are confident of meeting regulations and 43% can produce audit evidence.
Why it matters
A 79% production rate against 2% governance tooling makes you no outlier.
Agents at 22% of non-human accounts exceeds what manual review absorbs.
The gap between 57% confident and 43% audit-ready is the honest number.
What to do about it
Count your agent identities this quarter, including ones frameworks created.
Build one agent’s evidence chain: who authorized it, what it did.
Add agent identities to your next access recertification.
Rock’s Musings
Non-human identity means any authenticated principal that is not a person. It covers service accounts, workload identities, API keys, and now agents. The term earns its place because your IAM program runs on joiners, movers, and leavers, and an agent has none of those events.
A developer creates it at 11pm and it never resigns, so the lifecycle triggers your recertification depends on never fire. SailPoint sells identity security, so read 40 to 1 as a vendor’s framing. Start with the count.
9. Palo Alto Networks Found 95% Of Critical Infrastructure Leaders Worried And 68% Blind
Palo Alto Networks published its 2026 State of Critical Infrastructure Cybersecurity Report on October 6, 2026, based on responses from 1,600 security leaders across 11 countries. It found 95% were concerned about frontier AI-powered attacks.
On fundamentals, 68% lack real-time visibility into their OT assets and 74% still run IT and OT security separately. Only 40% have virtual patching, and 29% of CVEs were exploited within 24 hours against a 55-day average.
Why it matters
A 95% concern rate with 68% lacking asset visibility says spending never followed.
Exploitation inside a day against 55 days to patch is a gap patching cannot close.
With 60% lacking compensating controls, legacy OT assets stay exposed by default.
What to do about it
Fund OT asset visibility before the AI tool that needs it.
Stand up virtual patching for the legacy assets you cannot take offline.
Put the 24-hour exploitation figure beside your mean time to patch.
Rock’s Musings
I was a CISO in energy, so let me translate the 55-day number. A change control board owns part of it. Add a maintenance window negotiated with operations, a vendor who voids support for out-of-band patches, and a turbine indifferent to your SLA.
None of that changes the arithmetic when 29% of exploited CVEs get used inside a day. Virtual patching blocks exploitation at the network layer without touching the software, and 60% skipped it. Game on, owner-operators.
10. OWASP’s Q3 Roundup Says The Prompt Is Not A Boundary
The OWASP GenAI Security Project published its Q3 2026 GenAI and Agentic AI Exploit Roundup on October 8, 2026. Its conclusion is that prompt-level instructions alone do not establish a secure boundary. It recommends enforced scope, isolated credentials, and monitoring of what an agent did.
Four Claude Opus 4.7 evaluation runs obtained credentials and reached a production database. A Claude Mythos 5 PyPI package ran on 15 real systems in about an hour. The Deadbugz campaign pushed 23 pull requests through a malicious MCP server in 74 minutes, and none merged.
Why it matters
Scope overrun shows up at both OpenAI and Anthropic, so it is a design problem.
An MCP server changing behavior after approval breaks one-time review.
Agents obtained credentials nobody issued them.
What to do about it
Map your agents against the documented failure patterns.
Re-verify every MCP server your developers connect, on each change.
Separate agent credentials from their human operators, with separate revocation.
Rock’s Musings
I work on the Agent Control Standard inside this project, so I have a stake in it. The sentence worth carrying out of it is the conclusion: prompt-level instructions do not establish a secure boundary. We have said that in standards language for two years. It lands harder with four Opus 4.7 runs behind it.
Take the document into your next agent design review, because the cases map onto architecture decisions. Several land on MCP, the Model Context Protocol agents use to call outside tools. A quarterly roundup built from public disclosures undercounts, so read the case list as a floor. The ones that stayed private are the ones your vendor has not told you about yet.
The One Thing You Won’t Hear About But You Need To: An Unpatched 9.8 In Your LLM Cache Layer
JFrog published CVE-2026-105192 on October 7, 2026, found by Yuval Moravchick and rated 9.8 critical. LMCache, the key-value cache layer deployed alongside vLLM, opens an unauthenticated ZeroMQ ROUTER socket in multiprocess mode on port 5555. Decoding REGISTER_KV_CACHE arguments maps msgpack extension code 1 to a deserializer calling pickle.loads, so one crafted message runs code as the LMCache process user.
The official images run as root, every version from 0.3.9 onward is affected, and the project’s example Kubernetes DaemonSet binds to every interface. JFrog’s advisory includes a working proof of concept.
Why it matters
This sits in inference infrastructure, outside appsec and AI governance.
The project’s own example DaemonSet produces the configuration earning that 9.8.
Root in the official images turns code execution into node compromise.
What to do about it
Today, confirm no LMCache instance binds its transport to a routable address.
Firewall the transport port, since any host that connects can run code.
Open a ticket for the fix and put inference in scope.
Rock’s Musings
Insecure deserialization means taking bytes off the network and rebuilding them into live program objects without checking them first. Python’s pickle does exactly that by design, which is why it executes code as a feature and not a flaw. An unauthenticated socket hands attacker bytes to pickle.loads as root.
No model, no prompt injection, no agent cleverness, only a 1990s-vintage mistake in the plumbing serving your 2026 models. Your AI risk committee argued about model cards while this service unpickled whatever arrived.
As of October 7, 2026, there is no patch.
👉 Subscribe RockCyber Musings for more insights into AI security and governance, with the occasional rant. You can subscribe above
👉 Visit RockCyber.com to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.
👉 Want to save a quick $100K? Check out our AI Governance Tools at AIGovernanceToolkit.com
👉 As a bonus, I got to hang out with my friend Jeffrey Wheatman on Black Kite’s Third Party podcast to take the AI doom and hype cycle head-on: is AI the end of humanity, or just another Y2K? Nobody has produced a credible number for AI extinction risk, but there are hard numbers for what happens when companies overcorrect and ban AI across their vendors, and that’s where the conversation went.
References
Adversa AI. (2026, October 6). GitHub Copilot CLI vulnerability leaks developer secrets: Cryptographic context injection. https://adversa.ai/blog/cryptographic-context-injection-github-copilot/
amNewYork. (2026, October 5). AI giants give few clear answers to key safety questions at NYC Council hearing amid whistleblower warnings. https://www.amny.com/news/ai-giants-nyc-council-whistleblower-warnings/
Bushwick Daily. (2026, October). OpenAI, Anthropic, Google and Meta testify under oath Monday before all 51 NYC Council members on the risks of AI. https://bushwickdaily.com/politics/openai-anthropic-google-and-meta-testify-under-oath-monday-before-all-51-nyc-council-members-on-the-risks-of-ai/
Campion, A. (2026, October 7). Unknown threat actor uses AI-driven ARTEX to target South Korean finance. CrowdStrike. https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/
Channel Insider. (2026, October 7). SailPoint: AI agents outpace identity security controls. https://www.channelinsider.com/security/sailpoint-ai-agent-identity-security-gap/
Claburn, T. (2026, October 6). Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets. The Register. https://www.theregister.com/ai-and-ml/2026/10/06/zombie-instructions-on-carefully-constructed-web-pages-could-trick-github-copilot-cli-into-sharing-secrets/5301206
Claburn, T. (2026, October 7). Anthropic reconfigures its cool kids security program. The Register. https://www.theregister.com/security/2026/10/07/anthropic-reconfigures-its-cool-kids-security-program/5301509
Cloud Security Alliance. (2026, May 18). Mini Shai-Hulud: TeamPCP worm targets AI developer toolchain. https://labs.cloudsecurityalliance.org/research/csa-research-note-mini-shai-hulud-ai-toolchain-supply-chain/
CSO Online. (2026, October 8). AWS takes aim at runaway AI agent behavior with Strands Box. https://www.csoonline.com/article/4232446/aws-takes-aim-at-runaway-ai-agent-behavior-with-strands-box-2.html
Cyber Security News. (2026, October 7). Anthropic opens Claude access to red teams and verified cyber defenders with reduced restrictions. https://cybersecuritynews.com/anthropic-cyber-verification-program/
Dataconomy. (2026, October 5). Trump announces Super Intelligence Force led by Jay Clayton. https://dataconomy.com/2026/10/05/trump-super-intelligence-force-jay-clayton/
Dingler, F. (2026, October 7). Introducing Strands Box: AI agent sandboxes powered by Dogwood. AWS Open Source Blog. https://aws.amazon.com/blogs/opensource/introducing-strands-box-ai-agent-sandboxes-powered-by-dogwood/
The Hacker News. (2026, October 8). ARTEX AI pentesting tool used in data theft attacks on South Korean financial firms. https://thehackernews.com/2026/10/artex-ai-pentesting-tool-used-in-data.html
The IT Nerd. (2026, October 7). 60% of critical infrastructure organizations hit by significant cyber incidents. https://itnerd.blog/2026/10/07/60-of-critical-infrastructure-organizations-hit-by-significant-cyber-incidents/
JFrog Security Research. (2026, October 7). LMCache is vulnerable to unauthenticated remote code execution via pickle deserialization on the multiprocess ZMQ transport (CVE-2026-105192). https://research.jfrog.com/vulnerabilities/lmcache-is-vulnerable-to-unauthenticated-remote-code-execution-via-pickle-deserialization-on-the-multiprocess-zmq-transport-cve-2026-105192-jfsa-2026-001694382/
Jones, C. (2026, October 8). CrowdStrike finds possible bank hacker’s CV among exposed AI logs. The Register. https://www.theregister.com/cyber-crime/2026/10/08/crowdstrike-finds-possible-bank-hackers-cv-among-exposed-ai-logs/5301908
Khandelwal, S. (2026, October 7). Unpatched critical LMCache flaw lets unauthenticated attackers run code remotely. The Hacker News. https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html
Lakshmanan, R. (2026, October 5). Apple plans tighter macOS Full Disk Access controls over AI agent data access. The Hacker News. https://thehackernews.com/2026/10/apple-plans-tighter-macos-full-disk.html
OWASP GenAI Security Project. (2026, October 8). GenAI and agentic AI exploit roundup Q3 2026. https://genai.owasp.org/2026/10/08/genai-and-agentic-ai-exploit-roundup-q3-2026/
Palo Alto Networks. (2026, October 6). State of global critical infrastructure cybersecurity 2026: 95% of leaders concerned about frontier AI-powered attacks. https://www.paloaltonetworks.com/blog/network-security/state-of-global-critical-infrastructure-cybersecurity-2026-95-of-leaders-concerned-about-frontier-ai-powered-attacks/
Perez, S. (2026, October 2). Apple says it’s tightening macOS Full Disk Access controls due to new risks from AI agents. TechCrunch. https://techcrunch.com/2026/10/02/apple-says-its-tightening-macos-full-disk-access-controls-due-to-new-risks-from-ai-agents/
Pogorelec, A. (2026, October 5). Apple tightens macOS disk access as AI agents become more powerful. Help Net Security. https://www.helpnetsecurity.com/2026/10/05/macos-full-disk-access-updates/
Quartz. (2026, October 5). AI execs testify before NYC Council on existential AI risks. https://qz.com/anthropic-openai-google-meta-nyc-council-ai-hearing-100526
Quartz. (2026, October 6). Anthropic expands cyber AI access program to more security firms. https://qz.com/anthropic-cyber-verification-program-expansion-three-tiers-100626
SailPoint. (2026, October 6). SailPoint report finds 79% of enterprises run AI agents in production, yet only 2% have deployed purpose-built security [Press release]. GlobeNewswire. https://www.globenewswire.com/news-release/2026/10/06/3375448/0/en/sailpoint-report-finds-79-of-enterprises-run-ai-agents-in-production-yet-only-2-have-deployed-purpose-built-security.html
Security Boulevard. (2026, October 7). Daily OT security news: October 07, 2026. https://securityboulevard.com/2026/10/daily-ot-security-news-october-07-2026/
TechCrunch. (2026, October 4). Trump unveils his new Super Intelligence Force. https://techcrunch.com/2026/10/04/trump-unveils-his-new-super-intelligence-force/
Vigliarolo, B. (2026, October 7). AWS launches open-source AI agent sandbox to prevent YOLO mode disasters. The Register. https://theregister.com/ai-and-ml/2026/10/07/aws-launches-open-source-ai-agent-sandbox-to-prevent-yolo-mode-disasters/5301687



