The Autonomous Edge — Issue #7: Agentic Coding's Worm Problem Meets a Capital Surge Mandiant reported that an attacker hijacked an AI coding-assistant session and used it to spread the Shai-Hulud worm across roughly 100 internal code repositories at a SaaS provider, marking one of the first sourced cases of agentic coding tools serving as an active supply-chain attack vector. The incident landed the same week Temporal raised $550M at a $12.55B valuation and coding-agent startup Factory raised $200M at a $5B valuation, while Exaforce shipped runtime containment and kill-switch controls for AI agents. This week's developments Coding-assistant session hijacked, worm spreads across ~100 repos. Mandiant reported that an attacker hijacked an AI coding-assistant session and used it to spread the Shai-Hulud worm across roughly 100 internal code repositories at a SaaS provider. It's one of the clearest signals yet that agentic coding tools are becoming a live supply-chain attack vector rather than a theoretical risk — a hijacked, developer-trusted agent session becomes a ready-made lateral-movement tool. Source: The Hacker News https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html Temporal raises $550M at a $12.55B valuation. Temporal, the durable-execution orchestration platform increasingly used to keep long-running AI agent workflows reliable, closed a $550M Series E. The jump signals investors betting heavily on the reliability "plumbing" underneath agents, not just the agents themselves. Source: Temporal https://temporal.io/news/temporal-raises-550m-at-a-12-55b-valuation Coding-agent startup Factory triples valuation to $5B in five months. Factory, maker of AI coding agents "Droids" , raised $200M, tripling its valuation in under half a year. Paired with Temporal's raise, it's a reminder that capital is flowing to both the agents doing the work and the infrastructure keeping them reliable. Source: DevOps.com https://devops.com/factory-raises-200m-as-it-builds-agents-across-the-software-lifecycle/ Exaforce launches an AI agent "kill switch." Exaforce expanded its AI Security platform with runtime visibility and containment controls for AI agents and applications, from endpoint to cloud, including a kill-switch capability. It reads as a direct response to incidents like the Mandiant one above — as agents get more autonomy, security vendors are racing to ship the equivalent of an emergency stop. Source: Business Wire https://www.businesswire.com/news/home/20260915862377/en/Exaforce-Expands-Beyond-the-SOC-Into-AI-Security-Runtime-Visibility-and-Control-of-AI-Agents-and-Applications-From-Endpoint-to-Cloud Read across Security incidents and capital kept arriving in the same week. This is the first sourced case we've tracked of an AI coding session being hijacked as an active worm-propagation vector rather than a hypothetical one, and it landed the same week enterprise security vendors shipped kill switches and durable-execution infrastructure pulled in a $550M round. The pattern worth watching for enterprises: the tooling that makes agents useful — session persistence, repo access, autonomy — is the same tooling that makes them exploitable, and the market is now pricing both sides of that trade-off at once. For background on how agentic automation differs from the RPA it's replacing, browse our archive: https://buttondown.com/TheAutonomousEdge/archive https://buttondown.com/TheAutonomousEdge/archive If this was useful, forwarding it to one colleague who'd care is the best way to help it grow. Subscribe at https://buttondown.com/TheAutonomousEdge https://buttondown.com/TheAutonomousEdge Next issue: Monday, September 28, 2026.