Stories This Week
- Top Story — OWASP put a name and a risk list on the layer nobody governs: A "skill" is packaged expertise you hand an AI agent: instructions and scripts that turn a general assistant into one that knows how to build a landing page, close a support ticket, or run a deployment.
- A backdoor that starts when code is loaded, not when it is installed.: Developers have been taught for years to watch what happens during installation, because that is where malicious packages historically fired.
- Rust's turn came the same week, one layer deeper.: Someone got into the account of a maintainer whose code sits inside a large share of Rust projects and republished three of his libraries with one line added: a dependency on a package named one character off a near-universal one.
- Five federal agencies say AI is writing exploit code for the machines that run water plants.: The NSA, CISA, FBI, Department of Energy and EPA issued a joint advisory on August 19 about Siemens S7 controllers, the small industrial computers that physically open valves and run pumps.
- 🏛️ OpenAI stopped testing for two weeks and started rewriting its safety rulebook.: Axios reported on August 19 that OpenAI could not rule out that an unreleased model, Astra, had crossed the "critical" cybersecurity line in its own Preparedness Framework.
- 💰 Fortinet bought Virtue AI, and what it bought says where enterprises admit they are blind.: The August 17 deal folds agent discovery, continuous red-teaming of AI systems and runtime guardrails into Fortinet's security platform, per Fortinet's own account of what it bought.
- 🔬 A proposal to stop hand-writing agent defenses one rule at a time.: An August preprint argues runtime protection for AI agents cannot be hand-written fast enough, because the ways an agent can be pushed off task are open-ended while the rulebook defending it is finite.
- CSA AI Security Summit 2026: State of Trust, September 16–17.: A free two-day virtual event from the Cloud Security Alliance "exploring where cloud, AI, and Zero Trust converge.".
Curator's Corner
When a browser extension turns malicious, there is someone to call. Google can pull the listing, revoke the signature, and push the removal out to every machine that installed it. Unglamorous machinery, and it works. Ask the same three questions about the skills your agents loaded this morning and the room goes quiet. Who reviews them? Who signs them? Who can pull one back?
I have not found an answer, and this week made the gap harder to look away from.
Start with the fact that OWASP had to write a new list at all. The existing lists cover the model, and the protocol an agent uses to reach its tools. Neither covers the packaged behaviour that decides what those tools get used for. And the format proposed alongside the list reads as a request, field by field, for things that do not exist yet: a publisher identity, a signing key, a hash of the package, a declared permission set, a scan record. You do not draft that manifest for a layer that already has provenance.
Then the experiment. In June, Air Security researchers built a skill in under an hour that genuinely did what it promised, generating landing pages for non-technical staff. Its instructions sent the agent to fetch setup documentation from a domain they controlled. Then they collected the two signals people use to judge a skill. Scanner approval came free, because scanners read files and the payload was a link. Stars they borrowed, opening a pull request into a plugin marketplace repository with roughly 36,000 stars and a welcoming contribution policy: "after a few anxious days, it got merged." They ran an Instagram ad, swapped the documentation, and victim emails started arriving. Twenty-six thousand agents, including corporate ones. OWASP now cites that work as the real-world evidence behind its risk for untrusted external instructions. Niv Hoffman co-authored the research and is one of eight co-leads on the OWASP project.