Skip to content
Monday 2026-10-05 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

  • SonicWall SMA1000 Hit by Second Zero-Day Chain in Seven Weeks, Same SSRF-to-Injection Pattern

    SonicWall has disclosed a second zero-day chain affecting its SMA1000 series appliances within seven weeks. The vulnerabilities, detailed in SonicWall advisory SNWLID-2026-0016, consist of CVE-2026-83548, a pre-authentication server-side request forgery (SSRF) in the Appliance Work Place interface, and CVE-2026-83549, a post-authentication OS command injection in the AMC component. Both flaws are actively exploited in the…

  • NYSE Dual-Vendor Strategy Signals Institutional Shift in Tokenized Securities

    The Intercontinental Exchange is formalizing a two-vendor digital transfer agent program, positioning the New York Stock Exchange as the primary regulated venue for tokenized public equities. By signing a memorandum of understanding with tZERO on August 31, 2026, ICE has secured a premier design partner for its upcoming Digital Trading Platform. This follows the exchange’s…

  • Smart Home Security Debt: When Your Router Becomes the Agent’s Attack Surface

    The smart home hub sitting on your counter is marketed as a seamless command center for your life, promising to manage lights, locks, and climate with a simple voice prompt. It feels like a leap into the future, but that polished interface hides a crumbling foundation. August 2026 has been a brutal month for the…

  • MCP Security

    MCP Security is the discipline of identifying, mitigating, and managing the risks created by the Model Context Protocol — the open standard that connects AI agents to external tools, data sources, and APIs.

  • SEC Custody Rule Enters Final Review. Combined With Four Other Regulatory Tracks, the Institutional Stack Is Nearly Complete.

    The Securities and Exchange Commission’s custody modernization rule (RIN 3235-AN46) entered Office of Information and Regulatory Affairs review on August 25, marking the final procedural step before the Commission publishes a notice of proposed rulemaking. The NPRM is targeted for October 2026. On its own, this is a significant but incremental development. Viewed alongside four…

  • Coinbase’s Tokenized Stocks Are Live on Base. The SEC’s Framework Isn’t.

    Coinbase has launched tokenized U.S. equities on the Base blockchain. The August 24 rollout includes 13 stocks — NVDAc, METAc, AAPLc, GOOGLc, AMZN, COIN, CRCL, INTC, MSFT, MSTR, SNDK, SPCX, and TSLA — each representing a direct claim on the underlying share, not a synthetic derivative. The product is live. The U.S. regulatory framework that…

  • CVE-2026-76404: The MCP Security Wave Reaches Enterprise Infrastructure

    The security landscape for the Model Context Protocol (MCP) has reached a critical inflection point with the disclosure of CVE-2026-76404. This is the first critical vulnerability identified in a vendor-backed, enterprise-grade MCP server product, marking a departure from the experimental frameworks and open-source tools that have dominated the protocol’s early history. According to the official…

  • The SEC Is Writing Its Own Crypto Law. Congress Didn’t Ask It To.

    The Securities and Exchange Commission (SEC) has a peculiar way of signaling that the era of regulation-by-enforcement is nearing its expiration date. On August 18, 2026, the agency bypassed its own public meeting schedule, opting instead for a seriatim vote to release Regulation Crypto Assets (Release No. 33-11434). It was a quiet, surprise maneuver that…

  • The Agent Harness Emerges as the New Security Frontier

    Something broke in how we think about agent security. The recent disclosure of CVE-2026-18830 in the Amazon Bedrock AgentCore harness does not just patch a bug — it reveals a structural vulnerability class that the industry has not yet adequately named. The vulnerability is straightforward in concept but significant in implication. CVE-2026-18830 (CVSS v4.0: 8.6)…