AWS's Bedrock AgentCore Python SDK shipped fixes in v1.6.1 and v1.18.1 for one argument-injection flaw in install_packages(). Teams that let agents or users name packages for Code Interpreter sandboxes should check those names before the SDK sees them.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
OpenAI has fixed a Critical Codex flaw in which a semicolon in a branch name leaked the agent's GitHub OAuth token on all four Codex surfaces. How far one leaked token could reach was set by its scope, which is chosen by whoever provisions the agent.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence60
Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.
Perspective Coverage
4 publishers
- Builder
- Builder 33%
- Operator
- Operator 61%
- Investor
- Investor 6%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+30
- Incentives35
- Confidence65
Google's Threat Intelligence Group counted 141 flaws exploited in the wild from January to August, while monthly disclosures doubled to 10,740. Patch teams do better sorting by that exploited set than by the total, though attackers now reach some public flaws within days.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence50
The updated CISA-FBI advisory puts Medusa at more than 500 victims as of April 2026, up from 300, with exploits weaponized within 24 hours and sometimes a week before disclosure.
Perspective Coverage
7 publishers
- Builder
- Builder 12%
- Operator
- Operator 79%
- Investor
- Investor 9%
Reality
- Evidence76
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence74
Zimperium says the Android banking Trojan now abuses Accessibility to switch on wireless debugging and run commands through the ADB daemon. The target list is the smaller half of the story.
Perspective Coverage
6 publishers
- Builder
- Builder 28%
- Operator
- Operator 67%
- Investor
- Investor 5%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+12
- Incentives55
- Confidence64
Only 36% of IT staff in an Automox survey feel highly confident in their endpoint compliance visibility, as AI agents start acting on managed devices. Agents inherit their launcher's rights, so teams now need a record of what each may do and what it did.
Reality
- Evidence40
- Adoption50
- Hype gap+25
- Incentives80
- Confidence40
Adoption became routine before anyone settled who owns what the model produces. A BeyondTrust executive's column argues that a provider's licence leaves both the ownership question and a third party's claim wide open.
Reality
- Evidence58
- Adoption74
- Hype gap+12
- Incentives62
- Confidence54
OpenAI says the model never sees your password. BeyondTrust's Morey Haber told ZDNet that misses the point, because once the session exists an attacker can work inside it with all of your entitlements.
Reality
- Evidence60
- Adoption20
- Hype gap+28
- Incentives65
- Confidence55
A code injection flaw in Ray is now on CISA's mandatory fix list after BitSight saw a Mirai-derived botnet exploiting it. Compute clusters are being swept with the same traffic as routers.
Reality
- Evidence48
- Adoption55
- Hype gap+22
- Incentives52
- Confidence52
BeyondTrust's Morey Haber counts a 466.7% year-over-year rise in AI agents inside enterprises. They authenticate, hold privileges and move data, and insider-threat programs still assume a human.
Reality
- Evidence20
- Adoption
- Insufficient
- Hype gap+42
- Incentives85
- Confidence52
A public proof-of-concept for CVE-2026-54121 shows an Enterprise CA vouching for a forged Domain Controller identity. Microsoft's July 14 fix adds a missing check, not judgement.
Reality
- Evidence42
- Adoption22
- Hype gap+24
- Incentives78
- Confidence46