Skip to content
Saturday 2026-09-12 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

  • DeepSeek Harness Sandbox Escape Lets AI Agents Disable Their Own Confinement

    CVE-2026-82533 represents the first confirmed instance where an AI agent runtime sandbox has served as the direct attack surface for a vulnerability. Discovered by Nir Zadok and Moshe Siman Tov Bustan of OX Security, the flaw exists in DeepSeek Harness (dsh), an open-source, local-first coding agent tool that reached over 215,000 GitHub stars within weeks…

  • The CRA’s Agent Blind Spot Goes Live Tomorrow. Smart Home AI Companies Have Zero Guidance.

    Tomorrow morning, compliance teams across the smart home sector will wake up to a new, expensive reality. As of September 11, 2026, the Cyber Resilience Act (CRA) officially activates its reporting obligations. For companies managing smart door locks, security cameras, and virtual assistants—all classified as ‘important products’ under Annex III—the clock starts now. You have…

  • Three Threat Actor Clusters Including Sandworm Are Actively Exploiting Cisco FMC’s CVSS 10.0 Authentication Bypass

    Three distinct threat actor clusters are actively exploiting a critical authentication bypass in the Cisco Secure Firewall Management Center (FMC), identified as CVE-2026-20079. Cisco Talos reports that UAT-12197 is deploying web shells and a specific JAR file, cmd.jar, to facilitate credential theft via OmniQuery. Simultaneously, UAT-11823—linked to the Russian APT Sandworm (GRU Unit 74455)—is deploying…

  • Three Bills, Three Theories – A Fourth Theory Emerges from Florida

    Florida Attorney General James Uthmeier has introduced a legislative proposal that fundamentally alters the risk profile for the agent economy. By seeking to apply an existing aider-and-abettor statute to the developers and deployers of autonomous systems, the state is bypassing the ongoing federal debate over technical standards. This proposal, introduced on September 8, 2026, signals…

  • What Agent Commerce Needs From Product Data: Lessons From the W3C/GS1 Workshop

    An AI agent can navigate the entire digital funnel – searching, comparing, checking out, and executing payments – yet still fail at the point of purchase. This is the “last meter” problem, a structural friction point where the digital intent of an agent meets the physical reality of a product. If an agent cannot definitively…

  • Ant International, Visa, and Mastercard Agree on Agent Identity Standard. Now Comes the Hard Part.

    Autonomous commerce currently hits a wall at the identity layer. The fragmentation of protocols prevents AI agents from moving beyond experimental pilots into reliable financial execution. On September 10, 2026, Ant International, Visa, and Mastercard announced a Know Your Agent (KYA) interoperability framework in São Paulo to address this friction. The initiative targets cross-network operator…

  • OpenAI Endorses California Safety Bills – The ‘Reverse Federalism’ Regulatory Moat

    On September 9, 2026, OpenAI formally endorsed four specific California AI safety bills currently awaiting action from Governor Gavin Newsom. This legislative package includes SB 813, which mandates independent AI risk assessments; AB 1405, establishing rigorous standards for AI auditors; SB 1119, focused on child safety and parental controls; and AB 1864, which introduces safeguards…

  • Florida AG Proposes Criminal Liability for AI Chatbots That Aid Crimes – A New Front in Agent Governance

    Florida Attorney General James Uthmeier introduced a legislative proposal on September 8, 2026, that shifts the regulatory burden for artificial intelligence from abstract safety guidelines to direct criminal liability. By targeting companies that maintain practical control over the design, training, deployment, or safety settings of AI systems, the state is establishing a legal pathway to…

  • VPN Infrastructure Is Now the Authentication Gap’s Final Frontier

    The authentication gap has migrated to the outermost layer of enterprise infrastructure: the VPN. While previous waves of exploitation targeted middleware, identity providers, and endpoint management systems, the focus has shifted to the gateways that define the perimeter. Recent activity across Palo Alto, Check Point, Cisco, and Citrix confirms that VPN infrastructure is now the…

  • The Fed’s New Yardstick for Stablecoins

    For years, the debate surrounding stablecoins has been dominated by the mechanics of compliance and the looming threat of regulatory cliffs. However, a September 4, 2026, FEDS Note from Federal Reserve staff shifts the conversation from what issuers must do to what the central bank must measure. By establishing an analytical framework to evaluate these…