CyberXDefend counts about 11 named attacks on AI agent memory and learning, three of them demonstrated on production ChatGPT and OpenClaw. It found no confirmed criminal campaign, but in each case one poisoned write outlives the session, the property behind OWASP's ASI06 category.
Reality
- Evidence40
- Adoption20
- Hype gap+15
- Incentives50
- Confidence35
Vectorize CEO Chris Latimer says coding agents he used wrote API keys, credentials and sensitive documents into plain-text long-term memory. His attack scenario is hypothetical, and it still puts agent memory on the list of places where secrets live.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+30
- Incentives
- Insufficient
- Confidence35
Retried Buy clicks get the original order back in a dev.to guide that commits each order with its attempt key in one SQLite transaction. A disabled button only cuts double-clicks, and the guide's available text ends before it covers charging the card.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
OpenAI's August 19 update promises it keeps nothing after a request. The copies your own app leaves behind in logs, queues and databases are governed by you, not by a toggle.
Perspective Coverage
5 publishers
- Builder
- Builder 34%
- Operator
- Operator 35%
- Investor
- Investor 31%
Reality
- Evidence58
- Adoption15
- Hype gap+30
- Incentives65
- Confidence55
Qrator says x47.c, a Windows botnet sold for up to $950, burns a victim's OpenAI or xAI credit with a valid API key while the website stays up. Website filtering never sees the requests, so the defenses are key revocation and spending caps.
Perspective Coverage
3 publishers
- Builder
- Builder 35%
- Operator
- Operator 55%
- Investor
- Investor 10%
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence55
Dev.to author dharani2d argues agent security depends on who picks the next tool call, citing Excessive Agency's rise from sixth to third at OWASP. The proposed control plane keeps identity, authorization, argument checks and approvals in deterministic code outside the model.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence40
Three separate IDs and one Postgres row per retry let an investigator list every attempt for a tenant in order, according to a dev.to design. Adopting it means carrying an operation ID into every enqueue call, and its sample redactor lets bearer tokens through.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence45
Disclosure volume is climbing faster than the process around it. CISA's answer is a framework that describes what a good CVE record is and how the program should be judged on producing one.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 50%
- Investor
- Investor 17%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+30
- Incentives55
- Confidence66
Patrick Wardle published working code that sends Muse's dictated audio to a server of the attacker's choosing. Because the assistant holds file, microphone, camera, calendar and paired-iPhone access, whoever redirects it inherits all of it.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 54%
- Investor
- Investor 13%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence65
OWASP's August 3 edition added no categories and removed none, yet eight of the ten entries changed rank, with Unbounded Consumption up four places and Improper Output Handling down five. Prompt Injection still holds first.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+12
- Incentives70
- Confidence55
Forcepoint's unguarded research agent ran 500 tool calls for a simulated $10, a total set by the test's own ceiling, while the same scenario with a call budget, recursion cap and circuit breaker ended after one call and $0.02.
Reality
- Evidence42
- Adoption15
- Hype gap+30
- Incentives70
- Confidence45
A dev.to post keeps the spend ceiling in an authorization service the agent has no credential for, reserving each job's maximum charge before dispatch and accepting fewer concurrent admissions per period as the cost.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+5
- Incentives20
- Confidence55
Air Security's Plugin4Shell lets a plugin be swapped during a background refresh while the agent reports the audited commit. Anthropic and OpenAI have patched, Copilot has no fix, and Google is retiring Gemini CLI.
Reality
- Evidence60
- Adoption65
- Hype gap+20
- Incentives70
- Confidence58
A dev.to post argues that model-assisted analysis has made decompiled Android code cheap to understand, and proposes DEX encryption plus a native interpreter as the answer. Its own feature list shows what that costs to adopt.
Reality
- Evidence22
- Adoption
- Insufficient
- Hype gap+38
- Incentives76
- Confidence60
An architecture record for a health-data service spends one log event per deployment attempt, deriving the key fingerprint under an audit key held outside the log pipeline and holding the trail to 90 days.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap+8
- Incentives20
- Confidence48
An identity provider's history proves a factor challenge succeeded, so SOC 2 evidence for what the application decided next has to come from its own append-only event, with the policy version recorded at the moment of the decision.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives20
- Confidence50
The sixth item in OWASP's mobile list is rated low technical impact and severe business impact. A dev.to walkthrough argues React Native stacks carry extra exposure, and the reason it gives is the telemetry that arrives with dependencies.
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+22
- Incentives22
- Confidence46
A dev.to post argues the OWASP Top 10 for LLM Applications 2025 is a list of things a better model will not fix, including over-scoped permissions, unvalidated agent output, and retry loops that bill by the token.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+12
- Incentives30
- Confidence56
The startup's agents draft security policies and gather audit evidence, and its founders say a person still approves each policy while an independent auditor still signs the report.
Perspective Coverage
3 publishers
- Builder
- Builder 35%
- Operator
- Operator 35%
- Investor
- Investor 30%
Reality
- Evidence45
- Adoption52
- Hype gap+18
- Incentives74
- Confidence58
Cognito validates the redirect target by matching it against the app client's allowed callback list, so a development entry nobody removed is a valid destination for an authorization code, or for the tokens themselves where implicit grant is still on.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+35
- Incentives35
- Confidence50
Earlier coverage
- A sixty-line route table pins the two vendors an overnight LLM batch is allowed to reach
Build · September 13, 2026 · 1 publisher
- Security executives want AI agent limits enforced downstream of the model
Leadership · September 13, 2026 · 1 publisher
- Freezing new work before revoking the leaked key keeps the refusals explainable
Build · September 12, 2026 · 1 publisher
- Signed commits and commitlint move the first governance gate onto the developer's laptop
Build · September 11, 2026 · 1 publisher
- Where the agent runs decides whose guardrails apply
Build · September 10, 2026 · 1 publisher
- OWASP catalogues an attack that forges the approval dialog guarding AI agents
Science · September 10, 2026 · 1 publisher
- OWASP's Cornucopia mobile deck turns a card game into a MASVS requirements lookup
Build · September 10, 2026 · 1 publisher
- Prompt injection can rewrite the one-line summary in Claude Code's approval dialog
Build · September 9, 2026 · 1 publisher
- Advancing the credential version only after the password commits keeps reset requests powerless
Build · September 7, 2026 · 1 publisher
- IMDSv1 turns an SSRF finding into unauthenticated credential theft in one hop
Build · September 6, 2026 · 1 publisher
- CVE-2025-54136 turns a one-time MCP approval into a permanently mutable surface
Build · September 5, 2026 · 1 publisher
- AWS and SANS move agent authorization out of the prompt and into the RBAC layer
Security · September 3, 2026 · 1 publisher
- Delta-v leads a $100m round into runtime security for the coding agents enterprises already ship
Invest · September 2, 2026 · 2 publishers
- Why bounding the agent loop matters for a Well-Architected review
Build · August 30, 2026 · 1 publisher
- One trailing character that cannot match turns /^(a+)+$/ into a CPU pin
Build · August 29, 2026 · 1 publisher
- ClawHavoc's 12 accounts outshipped the malicious-skill census by 7.5 times
Invest · August 28, 2026 · 1 publisher
- An atomic claim on one flow record makes a duplicate OAuth callback harmless
Build · August 28, 2026 · 1 publisher
- The ICO fines what you cannot prove: Article 32 makes encryption and erasure an engineering liability
Build · August 26, 2026 · 1 publisher
- 93% have had an AI infrastructure incident. A quarter would still ship HCL unread.
Product · August 25, 2026 · 1 publisher
- An OAuth callback proves who logged in, not what the patient agreed to
Build · August 24, 2026 · 1 publisher
- MCP's roadmap fast-tracks five priorities and quietly queues everything else
Build · August 22, 2026 · 1 publisher
- If the model can move the CVSS score, the remediation queue is not auditable
Build · August 22, 2026 · 1 publisher
- An AI reviewer called injectable SQL safe because it could not read the helper
Build · August 19, 2026 · 1 publisher
- OWASP keeps prompt injection at number one and starts managing the blast radius
Security · August 18, 2026 · 1 publisher
- A docs bot that refuses to answer is working: the case for an evidence gate over a bigger window
Build · August 17, 2026 · 1 publisher
- The agent stack's attack surface is trust: pin the deps, audit the MCP servers
Build · August 16, 2026 · 1 publisher
- OWASP now names seventeen agentic threats, and the control unit is the whole run
Security · August 15, 2026 · 1 publisher