When the AI agent can edit the evidence
A study published on arXiv on September 24, "LLM Agents Can Easily Tamper With Their Own Traces," found that coding agents in seven of eight popular harnesses deleted their own session traces when ask…
A study published on arXiv on September 24, "LLM Agents Can Easily Tamper With Their Own Traces," found that coding agents in seven of eight popular harnesses deleted their own session traces when ask…
OpenAI disclosed that 16,000 extraction requests using a relevant extraction pattern hit its API on July 24 and 25 from more than 4,000 accounts — roughly four requests each — and traced related promp…
Google's Fairwind Program grants vetted cyber defenders early access to Gemini 4 Argon with its cyber guardrails disabled, under governance rules requiring background checks, phishing-resistant MFA, a…
OpenAI's plugin troubleshooting guide recommends isolating failed ChatGPT plugin actions to the responsible layer — server, component, or ChatGPT client — and collecting server logs, component-console…
OpenAI said at its September 29 DevDay that ChatGPT is adding draft MCP Events support, letting MCP servers notify the client via `events/subscribe` and webhook delivery, with the feature listed for a…
OpenAI announced plugin extensions at DevDay on September 29, 2026, letting developers add sidebar apps and conversation panels to ChatGPT and publish them to a shared plugin directory serving ChatGPT…
Microsoft's Digital Crimes Unit announced on September 22 that it disrupted EvilTokens, a phishing-as-a-service platform that compromised more than 12,000 inboxes at over 10,000 organizations since it…
WorkOS released a CLI command, `workos mcp install`, that writes the WorkOS MCP server definition at `https://mcp.workos.com/mcp` into Claude Code, Codex, and Cursor in a single run, with no API key o…
The IETF's competing SCIM agent-identity drafts consolidated into a single document, draft-wzdk-scim-agent-resource-00, published in June 2026 and co-authored by M. Wahl and P. Dingle of Microsoft, D.…
WorkOS published a 2026 AI agent permissions checklist for SaaS apps, organized by lifecycle stage from design to revocation, with eight core controls including giving every agent its own identity sep…
Ox Security's registry audit, published in a report titled "15,465 MCP Servers, 0 Governance," counted 15,465 MCP servers across the official MCP registry, the Cline marketplace, and the GitHub MCP re…
The official Model Context Protocol TypeScript SDK released version 2.1.0, adding DPoP sender-constrained access tokens (RFC 9449, shipped as SEP-1932) and request-time OAuth scope challenges from the…
Datadog Security Labs disclosed in October 2025 that Microsoft Copilot Studio could be abused as an OAuth phishing vector, with agents hosted on the trusted copilotstudio.microsoft.com domain able to …
WorkOS released Airlock in early access, a system that combines deterministic rules with runtime AI judgment to govern AI agent actions, according to a WorkOS guide built on Aaron Tainter's Gmail demo…
WorkOS launched Airlock in early access, an intent-based access control system that evaluates AI agent actions against declared intent and configured policies before API calls proceed. In a demo by Aa…
Anthropic's documentation states that a typical multiserver MCP setup spanning GitHub, Slack, Sentry, Grafana, and Splunk consumes roughly 55,000 tokens in tool definitions before the model does any w…
LiteLLM patched CVE-2026-59822, an authentication bypass in its MCP endpoint rated 8.8 High on CVSS 4.0 that affected every version below 1.84.0 and was added by CISA to the Known Exploited Vulnerabil…
Removing MCP servers in favor of direct API access eliminates the only publicly specified layer for user-delegated, audience-bound, revocable agent authorization, leaving agents back on long-lived key…
Voice AI agents such as Gemini 3.8 Live Extended Thinking, which shipped September 15, 2026, execute tools and API calls in the background while narrating the work aloud, leaving no out-of-band channe…
Non-human identities such as API keys, service accounts, and AI agents now outnumber employees at most organizations, and roughly 91 percent of organizations already use AI agents in some form while o…