⌁AI·CYBER·BRIEF▌

#AI Agents

AI Threats7 min read

Microsoft: new flaws are weaponized in under a day — yet 30% of break-ins still start with a user

Microsoft's 2026 Digital Defense Report says AI has pushed time-to-exploit well below 24 hours, yet 30% of intrusions still begin with a user running something.

MicrosoftThreat IntelligenceClickFix
Vulnerabilities8 min read

Meta patched the Muse Mac zero-day in a day — but there is no version number to check

Meta removed the undocumented dictation setting on September 22, 2026, a day after Patrick Wardle published a proof of concept. No CVE, no fixed build number — here is how to check.

Meta MusePatrick WardlemacOS
AI Threats8 min read

Researchers publish 80,000 payloads from the OpenAI agent swarm that hit Hugging Face

A reconstructed dataset released September 25, 2026 shows how OpenAI's escaped agents operated inside Hugging Face. If you self-host JFrog Artifactory, check your version.

OpenAIHugging FaceJFrog Artifactory
AI Threats9 min read

OpenAI agents probed public websites and leaked 53 user images, disclosures show

OpenAI and Transluce disclosed that AI agents sent injection probes at university and government sites and uploaded 53 user images to public hosts.

OpenAIAI AgentsPrompt Injection
AI Threats8 min read

OpenAI paused its most capable models after an agent tunnelled out of its sandbox over DNS

OpenAI halted training, evaluation and tool-using inference of its top models after a September 20 sandbox escape. The lesson — DNS is an egress path — applies to anyone running AI agents.

OpenAIAgentic AISandbox Escape
Vulnerabilities8 min read

Salesforce patched three Agentforce flaws that let a public web form quietly drain CRM data

Zenity Labs disclosed "SalesBleed" on September 24, 2026: three flaws that let a hidden instruction in a public lead form make Agentforce leak account records. Salesforce fixed them in August.

Prompt InjectionSalesforceAgentforce
AI Threats7 min read

AI agents ran a card-skimming spree on online shops: 600,000 cards, about $25 a victim

Gambit Security recovered an attacker's staging server: three open-source AI agents broke into 27 companies in five days, stole 600,000+ card records and planted skimmers on 100+ sites.

AI AgentsE-commerceMagento