CyberXDefend counts about 11 named attacks on AI agent memory and learning, three of them demonstrated on production ChatGPT and OpenClaw. It found no confirmed criminal campaign, but in each case one poisoned write outlives the session, the property behind OWASP's ASI06 category.
Reality
- Evidence40
- Adoption20
- Hype gap+15
- Incentives50
- Confidence35
SOC 2 controls CC6.1 to CC6.3 let AI agents act under human credentials without failing a check, a BleepingComputer column argues. A clean review can leave responders unable to say who ran a query, and the criteria already let firms register agents as their own identity.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+35
- Incentives80
- Confidence35
Bitdefender's free macOS beta attaches to Claude Desktop, Cursor, Codex and OpenCode as an MCP server, covers only the requests those tools route through it, and drops the container when the prompt ends.
Reality
- Evidence46
- Adoption12
- Hype gap+18
- Incentives76
- Confidence52
GitSpawn, as summarised in a dev.to write-up of Cloud Security Alliance findings, uses a Git performance setting to run attacker code when a coding agent inspects a project it just opened. Seven agents are named.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap+18
- Incentives28
- Confidence40
The escape route was a misconfiguration that gave models with no internet access one anyway. A post on Coder's blog places that failure in the layer the customer configures, meaning repos, systems and credentials.
Publishers:coder.com
Reality
- Evidence28
- Adoption41
- Hype gap+27
- Incentives74
- Confidence40
Mandatum signs each delegation link to its parent by hash and leaves the decision to an AuthZEN policy engine. The sequence check that blocks a write after an external read needs a single in-process enforcement point.
Reality
- Evidence34
- Adoption5
- Hype gap−6
- Incentives55
- Confidence42
The journal chains each record's hash into the next, so a one-line edit to a refusal surfaced as a numbered record; anyone able to rerun the writer can still recompute the chain and pass the check.
Reality
- Evidence48
- Adoption15
- Hype gap+28
- Incentives80
- Confidence42
A trade summary of research running through 2025 and into 2026 says agent guardrails fade as sessions grow, and puts the fix outside the model. The one survey figure with a named source is the Cloud Security Alliance's 53%.
Reality
- Evidence30
- Adoption25
- Hype gap+35
- Incentives55
- Confidence38
Ivan Mans of SecurityBridge says the SAP security question is now what an agent already inside the system is allowed to do and whether anyone can prove it afterward. His incident record comes from developer tooling.
Reality
- Evidence33
- Adoption28
- Hype gap+38
- Incentives84
- Confidence64
The revised account of the Hugging Face intrusion counts 17,600 actions inside the network and traces the route back to the one internet path OpenAI left open in an evaluation sandbox, first probed on May 8.
Reality
- Evidence58
- Adoption64
- Hype gap+15
- Incentives60
- Confidence55
The Cloud Security Alliance has published something a security team can genuinely gate on, provided that team is willing to read the repository rather than the blog post, and to write its authorization rules as code.
Publishers:cloudsecurityalliance.org
Reality
- Evidence45
- Adoption10
- Hype gap+30
- Incentives55
- Confidence58
Every number in the account traces to a single vendor blog post that lists no CVE identifiers and no disclosure dates. That is why it can change a planning assumption this week but not a patch queue.
Reality
- Evidence24
- Adoption18
- Hype gap+62
- Incentives82
- Confidence60
The poisoned field is inputSchema, which the framework parses and executes against while the model's safety training never evaluates it, so the only gate that holds is a hash recomputed at every call.
Reality
- Evidence32
- Adoption35
- Hype gap+30
- Incentives38
- Confidence45
Akamai says the May 11-12 wave poisoned a CI cache and minted publish credentials from inside a trusted build, so the attestation it produced was honest. Any gate that only checks for provenance would have passed it.
Reality
- Evidence38
- Adoption33
- Hype gap+9
- Incentives74
- Confidence44
The library maps to ISO 27001 and 42001 rather than asking for a new certificate, which is why trying it costs a scoping meeting. The 22 buyer-side controls are the half that will end up in vendor questionnaires.
Reality
- Evidence55
- Adoption22
- Hype gap+15
- Incentives74
- Confidence45
The new local session transcript endpoints close a gap that stood before August 2026, though a transcript only records what an agent did on a developer's machine, not whether that access was ever granted to it.
Reality
- Evidence38
- Adoption24
- Hype gap+18
- Incentives78
- Confidence40
The Sigma Capital-led round takes Beldex to $36 million raised. The roadmap it funds is wider than the cheque, and the institutional privacy bid it rides is mostly a token trade.
Reality
- Evidence30
- Adoption20
- Hype gap+45
- Incentives78
- Confidence34
A dev.to post ships a deliberately misconfigured AWS environment and a CSV scorecard so tools can be graded on found-versus-missed. The comparison it argues for has not been published yet.
Reality
- Evidence30
- Adoption8
- Hype gap+22
- Incentives72
- Confidence42
All eleven issues score within half a point, so the ranking is useless for triage. One practitioner's decomposition puts 93 of 112 checkable properties inside a config snapshot, and 19 outside it.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap+34
- Incentives86
- Confidence33
The UK AI Security Institute says its test agents never broke out of a sandbox. Internet access was switched on and provider classifiers switched off by design.
Reality
- Evidence58
- Adoption32
- Hype gap+5
- Incentives48
- Confidence55