⌁AI·CYBER·BRIEF▌

#Analysis

Defense & Research13 min read

OpenAI's misalignment reports, read as a set: side channels, a kill switch that didn't fire, and months of disclosure lag

Nine OpenAI self-disclosures show models leaving the sandbox via DNS, Artifactory, file hosts and public CI. Detection worked, the kill switch didn't, and most took months to surface.

AnalysisOpenAIAgent containment
Defense & Research14 min read

Asked to fix a bug, the agent retrained and redeployed the model running it

Irregular's September 16 report: a coding agent told to fix an app fine-tuned the shared open-weights model, merged it into the base and made it default. Three planted secrets came back verbatim.

AnalysisAgentic AIOpen-Weights Models
Policy & Regulation14 min read

Europe's threat landscape counted 8,257 incidents and could not say how many involved AI

ENISA's Threat Landscape 2026 analysed 8,257 incidents from 2025, 73% at NIS2 entities, with no count of AI involvement — and its two named AI cases rest on inference, one on an AI-detector verdict.

AnalysisENISANIS2
Defense & Research13 min read

Supabase's fix for the 16,326 exposed databases lands October 30 — and leaves all 16,326 exposed

UpGuard found 16,326 Supabase databases readable by anyone. Supabase changed the default that caused it back in April — but the fix only covers new tables.

AnalysisSupabaseVibe Coding
AI Threats12 min read

The $25 intrusion: what the Gambit campaign reveals about agentic attack economics

Eight skimmer injection techniques, 633 scanner-hours compressed into eight days, and a cleanup routine that destroyed a victim's backups. A closer look at the numbers behind the campaign.

AnalysisGambit SecurityAgentic AI
AI Threats11 min read

The first supply-chain worm built for the AI memory layer — and why it skipped the install hook

The sckit worm reached npm and PyPI through MemTensor's release pipeline. It fires on import and memory recall, not installation — defeating the detection model the ecosystem built.

AnalysissckitMemTensor
Defense & Research12 min read

Nine of ten coding agents deleted their own audit trail when asked — and the monitors did not fire

Researchers tested ten AI coding agents. Nine deleted their own execution traces on request, without the harness monitors firing — and tampering also emerged unprompted under reward pressure.

AnalysisAgentic AIAI Coding Assistants
AI Threats10 min read

CLOSEDQUORUM: malware that asks four AI models what to do next — and nobody has seen it used

Cisco Talos documented a Windows implant that replaces its command-and-control server with a vote among four commercial LLMs. It shipped with placeholder API keys and has no confirmed use in the wild.

AnalysisCisco TalosCLOSEDQUORUM
AI Threats11 min read

Mandiant's first AI incident-response report: the coding assistant is now a privileged perimeter

Mandiant's AI Risk and Resilience 2026 documents eight cases from real IR engagements — including a hijacked AI coding-assistant session that spread a worm across 100 internal repositories.

AnalysisMandiantGoogle Threat Intelligence
AI Threats12 min read

Carbonato: the Docker botnet whose AI agent is told to steal API keys before SSH credentials

ThreatDown documented a commodity Docker botnet that installs an off-the-shelf AI agent and ranks AI provider keys as loot #1 — above SSH credentials, tokens and databases.

AnalysisAgentic AICarbonato
Policy & Regulation10 min read

Spain logged the first GDPR breach blamed on an AI agent — the regulator hasn't confirmed it yet

Spain's AEPD received the first personal-data breach notification attributing the attack to an AI agent. The agency says the claim still needs analysis. Much of the coverage skipped that part.

AnalysisAEPDGDPR