Skip to content
Wednesday 2026-10-07 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

  • StyleSmuggler Turns Adobe Commerce’s Own Template Engine Into an Unauthenticated RCE Chain

    Nine 48-byte datagrams, spaced 10 milliseconds apart, arrive every 60 seconds. To a standard network monitor, this looks like routine NTP traffic. To the Rust-based implant behind CVE-2026-75650, it is a heartbeat. This is StyleSmuggler, a critical vulnerability in Adobe Commerce and Magento 2.4.4 through 2.4.9 that has turned the platform’s own template-processing logic into…

  • Salesforce Formalizes the Agent Governance Stack Into a Single Platform

    Most enterprise AI initiatives are currently stuck in a cycle of pilot projects that never reach production. Data from IDC and Lenovo suggests that 88% of enterprises with agent initiatives never ship to production, while Gartner reports that over 40% of agentic AI projects are cancelled due to escalating costs and inadequate risk controls. For…

  • Positron AI’s $875M Bet: Commodity Memory Could Break NVIDIA’s Inference Lock

    Positron AI has raised $875 million in a combined Series C and Series C-1 round, valuing the Reno-based startup at $5 billion post-money. The financing, co-led by NEA, Andra Capital, Atreides Management, Valor Equity Partners, and SemiAnalysis Capital, represents a roughly five-fold markup from the company’s February 2026 Series B valuation of just over $1…

  • The Enforcement Wave: Five Deadlines That Will Define AI Agent Governance This Year

    Tomorrow, September 11, the European Union’s Cyber Resilience Act activates its first concrete enforcement mechanism. Under Article 14, manufacturers placing products with digital elements on the EU market must notify ENISA and the designated national CSIRT within 24 hours of discovering an actively exploited vulnerability or severe incident. A fuller notification follows within 72 hours.…

  • DeepSeek Harness Sandbox Escape Lets AI Agents Disable Their Own Confinement

    CVE-2026-82533 represents the first confirmed instance where an AI agent runtime sandbox has served as the direct attack surface for a vulnerability. Discovered by Nir Zadok and Moshe Siman Tov Bustan of OX Security, the flaw exists in DeepSeek Harness (dsh), an open-source, local-first coding agent tool that reached over 215,000 GitHub stars within weeks…

  • The CRA’s Agent Blind Spot Goes Live Tomorrow. Smart Home AI Companies Have Zero Guidance.

    Tomorrow morning, compliance teams across the smart home sector will wake up to a new, expensive reality. As of September 11, 2026, the Cyber Resilience Act (CRA) officially activates its reporting obligations. For companies managing smart door locks, security cameras, and virtual assistants—all classified as ‘important products’ under Annex III—the clock starts now. You have…

  • Three Threat Actor Clusters Including Sandworm Are Actively Exploiting Cisco FMC’s CVSS 10.0 Authentication Bypass

    Three distinct threat actor clusters are actively exploiting a critical authentication bypass in the Cisco Secure Firewall Management Center (FMC), identified as CVE-2026-20079. Cisco Talos reports that UAT-12197 is deploying web shells and a specific JAR file, cmd.jar, to facilitate credential theft via OmniQuery. Simultaneously, UAT-11823—linked to the Russian APT Sandworm (GRU Unit 74455)—is deploying…

  • Three Bills, Three Theories – A Fourth Theory Emerges from Florida

    Florida Attorney General James Uthmeier has introduced a legislative proposal that fundamentally alters the risk profile for the agent economy. By seeking to apply an existing aider-and-abettor statute to the developers and deployers of autonomous systems, the state is bypassing the ongoing federal debate over technical standards. This proposal, introduced on September 8, 2026, signals…

  • What Agent Commerce Needs From Product Data: Lessons From the W3C/GS1 Workshop

    An AI agent can navigate the entire digital funnel – searching, comparing, checking out, and executing payments – yet still fail at the point of purchase. This is the “last meter” problem, a structural friction point where the digital intent of an agent meets the physical reality of a product. If an agent cannot definitively…