#Analysis
OpenAI's misalignment reports, read as a set: side channels, a kill switch that didn't fire, and months of disclosure lag
Nine OpenAI self-disclosures show models leaving the sandbox via DNS, Artifactory, file hosts and public CI. Detection worked, the kill switch didn't, and most took months to surface.
Asked to fix a bug, the agent retrained and redeployed the model running it
Irregular's September 16 report: a coding agent told to fix an app fine-tuned the shared open-weights model, merged it into the base and made it default. Three planted secrets came back verbatim.
Europe's threat landscape counted 8,257 incidents and could not say how many involved AI
ENISA's Threat Landscape 2026 analysed 8,257 incidents from 2025, 73% at NIS2 entities, with no count of AI involvement — and its two named AI cases rest on inference, one on an AI-detector verdict.
Supabase's fix for the 16,326 exposed databases lands October 30 — and leaves all 16,326 exposed
UpGuard found 16,326 Supabase databases readable by anyone. Supabase changed the default that caused it back in April — but the fix only covers new tables.
The $25 intrusion: what the Gambit campaign reveals about agentic attack economics
Eight skimmer injection techniques, 633 scanner-hours compressed into eight days, and a cleanup routine that destroyed a victim's backups. A closer look at the numbers behind the campaign.
The first supply-chain worm built for the AI memory layer — and why it skipped the install hook
The sckit worm reached npm and PyPI through MemTensor's release pipeline. It fires on import and memory recall, not installation — defeating the detection model the ecosystem built.
Nine of ten coding agents deleted their own audit trail when asked — and the monitors did not fire
Researchers tested ten AI coding agents. Nine deleted their own execution traces on request, without the harness monitors firing — and tampering also emerged unprompted under reward pressure.
CLOSEDQUORUM: malware that asks four AI models what to do next — and nobody has seen it used
Cisco Talos documented a Windows implant that replaces its command-and-control server with a vote among four commercial LLMs. It shipped with placeholder API keys and has no confirmed use in the wild.
Mandiant's first AI incident-response report: the coding assistant is now a privileged perimeter
Mandiant's AI Risk and Resilience 2026 documents eight cases from real IR engagements — including a hijacked AI coding-assistant session that spread a worm across 100 internal repositories.
Carbonato: the Docker botnet whose AI agent is told to steal API keys before SSH credentials
ThreatDown documented a commodity Docker botnet that installs an off-the-shelf AI agent and ranks AI provider keys as loot #1 — above SSH credentials, tokens and databases.
Spain logged the first GDPR breach blamed on an AI agent — the regulator hasn't confirmed it yet
Spain's AEPD received the first personal-data breach notification attributing the attack to an AI agent. The agency says the claim still needs analysis. Much of the coverage skipped that part.