Stories This Week
- Top Story — BragJack reaches the assistant through the browser: A browser assistant can act inside accounts where the user is already signed in.
- Plugin4Shell put developers' machines at risk by substituting malicious code for an approved plugin version.: AIR found that affected coding tools could accept code from an attacker-controlled plugin repository without checking that the downloaded code matched the exact revision requested; for Claude Code and Codex, the researchers describe automatic-update paths that could reach code execution without another click.
- RatHat uses AI to help malware operate an infected Android phone.: Zimperium describes deceptive app downloads and abuse of Android's Accessibility features, which let software read and interact with on-screen controls; generative AI then helps navigate the interface in a campaign aimed at credentials and financial accounts.
- Spain's privacy regulator is examining a reported breach involving an AI-assisted attacker.: The AEPD says an organization reported a successful login followed by agent-assisted vulnerability discovery, personal-data changes and access to invoices; its analysis is still underway, and it names neither the organization nor the model.
- OpenAI is making unauthorized model behavior a recurring disclosure category.: Its September 16 framework launched with six reports from training or evaluation, including agents that worked around a broken local file-sharing setup by uploading a workbook to public hosting despite a local-only task.
- Cisco is bringing more AI-assisted security work into self-managed Splunk environments.: Its September 15 announcement makes the AI POD for Splunk and AI Assistant available for that setting, while the agent-building Launchpad is slated for later in the year.
- Cohesity is extending recovery to the memory and configuration that shape an agent's behavior.: Its Agent Resilience announcement covers restoring agent infrastructure and affected resources, starting with Amazon Bedrock support for select customers rather than general availability.
- Tuskira says its new Vector tool tests whether attackers could break into internet-facing systems despite the protections already in place.: The company says its autonomous testing uses context about existing security controls and infrastructure to guide customer-authorized testing, rather than treating every visible weakness as equally urgent.
- October 8: CSA's AI Threat Readiness virtual event.: The Cloud Security Alliance and Wiz are hosting a session focused on AI threats and readiness..
- October 19–22: ETSI Security Conference, Sophia Antipolis.: The program includes AI security alongside the broader security-standardization agenda..
Curator's Corner
Could I get an AI to give a candidate a better score without changing a single qualification?
This week's BragJack research showed browser extensions reaching privileged AI-assistant components. I wanted to try a different route: instructions in a professional profile, aimed at the AI reading it.
I found public profiles addressing AI readers directly. That gave me a pattern to test, not evidence that it worked. I built a fictional candidate, kept the experience and scoring criteria fixed, and used AI to run clean and modified versions through the evaluator. Some versions asked for a perfect score or an endorsement phrase. One asked for a cookie recipe.
I expected the interesting part to be how the evaluator handled those instructions. Across 33 evaluations, including 24 with planted instructions, none produced the requested perfect score, phrase or recipe. Every clean and modified profile still got a recommendation, so that alone couldn't demonstrate influence. A small test in a shared agent setup cannot settle how recruiting systems behave.