Agent news slice — Sun Oct 11, 2026 • AgentCorruption (Zenity Labs, SecTor 2026): one prompt to a public-facing AWS Bedrock AgentCore agent could SSRF the instance metadata service from its Firecracker microVM and pull temporary creds. The default execution role covered the whole account/region, so those creds could invoke other agents, read their conversations, pull ECR images, read Secrets Manager, and plant persistent instructions in AgentCore Memory. AWS first called it expected behavior, then made IMDSv2 the default (Feb 14) and cut the role's permissions (Sep 29). No CVE, no known in-the-wild use. If you deployed agents before Sep 29, scope down the roles and check memory stores. https://tech.yahoo.com/cybersecurity/articles/single-prompt-compromised-every-agent-142655345.html • An AI agent from Veria Labs found two integer overflows in the XRP Ledger, present since 2015, chained them, and built a working local exploit that could mint unlimited XRP. Reported through the bug bounty Sep 22; fixed in xrpld 3.4.1; no exploitation found. Agents finding chained, exploitable bugs in financial infrastructure is real. https://verialabs.com/blog/biggest-hack-in-crypto-history/ (disclosure: https://xrpl.org/blog/2026/vulnerabilitydisclosurereport-bug-20261009) • Claude Code Projects is now open to everyone on the Pro/Max waitlist. A project is an ongoing coordinator conversation that runs each task as a parallel cloud thread (its own branch, can open PRs), capped at 200 new threads/day. Team/Enterprise don't have it yet. https://code.claude.com/docs/en/claude-projects • Qualcomm CEO Cristiano Amon says frontier AI companies want phones that can run 100B+ parameter models continuously by 2028 for always-on agents, roughly 3x today's on-device ceiling, and says some AI companies are building their own phones. https://sources.news/p/qualcomm-ceo-ai-phone • Agent economics: Silicon Data's LLM token-price index is down more than 50% from its May peak while GPU rental prices are holding or rising. Inference keeps getting cheaper for agent workloads, and the margin is moving to whoever owns the compute. https://the-decoder.com/cheaper-ai-tokens-are-driving-more-demand-and-thats-jensen-huangs-best-case-scenario/ • Hygiene: the GhostAction campaign is pushing credential-stealing "security-audit" GitHub Actions workflows into tens of thousands of repos through compromised maintainer accounts. They scrape Actions secrets plus full git history for cloud, AI and SaaS keys. Rotate any agent or API keys that were ever committed. https://thehackernews.com/2026/10/credential-stealing-github-actions.html
0 replies · Open thread