cd /news/ai-agents/the-autonomous-edge-issue-7-agentic-… · home topics ai-agents article
[ARTICLE · art-135905] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

The Autonomous Edge — Issue #7: Agentic Coding's Worm Problem Meets a Capital Surge

Mandiant reported that an attacker hijacked an AI coding-assistant session and used it to spread the Shai-Hulud worm across roughly 100 internal code repositories at a SaaS provider, marking one of the first sourced cases of agentic coding tools serving as an active supply-chain attack vector. The incident landed the same week Temporal raised $550M at a $12.55B valuation and coding-agent startup Factory raised $200M at a $5B valuation, while Exaforce shipped runtime containment and kill-switch controls for AI agents.

read2 min views1 publishedSep 21, 2026

This week's developments

Coding-assistant session hijacked, worm spreads across ~100 repos. Mandiant reported that an attacker hijacked an AI coding-assistant session and used it to spread the Shai-Hulud worm across roughly 100 internal code repositories at a SaaS provider. It's one of the clearest signals yet that agentic coding tools are becoming a live supply-chain attack vector rather than a theoretical risk — a hijacked, developer-trusted agent session becomes a ready-made lateral-movement tool. (Source: The Hacker News)

Temporal raises $550M at a $12.55B valuation. Temporal, the durable-execution orchestration platform increasingly used to keep long-running AI agent workflows reliable, closed a $550M Series E. The jump signals investors betting heavily on the reliability "plumbing" underneath agents, not just the agents themselves. (Source: Temporal)

Coding-agent startup Factory triples valuation to $5B in five months. Factory, maker of AI coding agents ("Droids"), raised $200M, tripling its valuation in under half a year. Paired with Temporal's raise, it's a reminder that capital is flowing to both the agents doing the work and the infrastructure keeping them reliable. (Source: DevOps.com)

Exaforce launches an AI agent "kill switch." Exaforce expanded its AI Security platform with runtime visibility and containment controls for AI agents and applications, from endpoint to cloud, including a kill-switch capability. It reads as a direct response to incidents like the Mandiant one above — as agents get more autonomy, security vendors are racing to ship the equivalent of an emergency stop. (Source: Business Wire)

Read across

Security incidents and capital kept arriving in the same week. This is the first sourced case we've tracked of an AI coding session being hijacked as an active worm-propagation vector rather than a hypothetical one, and it landed the same week enterprise security vendors shipped kill switches and durable-execution infrastructure pulled in a $550M round. The pattern worth watching for enterprises: the tooling that makes agents useful — session persistence, repo access, autonomy — is the same tooling that makes them exploitable, and the market is now pricing both sides of that trade-off at once.

For background on how agentic automation differs from the RPA it's replacing, browse our archive: [https://buttondown.com/TheAutonomousEdge/archive](https://buttondown.com/TheAutonomousEdge/archive)

If this was useful, forwarding it to one colleague who'd care is the best way to help it grow.

Subscribe at [https://buttondown.com/TheAutonomousEdge](https://buttondown.com/TheAutonomousEdge)

Next issue: Monday, September 28, 2026.

── more in #ai-agents 4 stories · sorted by recency
── more on @mandiant 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/the-autonomous-edge-…] indexed:0 read:2min 2026-09-21 ·