Skip to content
Sunday 2026-09-13 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

  • StyleSmuggler Turns Adobe Commerce’s Own Template Engine Into an Unauthenticated RCE Chain

    Nine 48-byte datagrams, spaced 10 milliseconds apart, arrive every 60 seconds. To a standard network monitor, this looks like routine NTP traffic. To the Rust-based implant behind CVE-2026-75650, it is a heartbeat. This is StyleSmuggler, a critical vulnerability in Adobe Commerce and Magento 2.4.4 through 2.4.9 that has turned the platform’s own template-processing logic into…

  • Salesforce Formalizes the Agent Governance Stack Into a Single Platform

    Most enterprise AI initiatives are currently stuck in a cycle of pilot projects that never reach production. Data from IDC and Lenovo suggests that 88% of enterprises with agent initiatives never ship to production, while Gartner reports that over 40% of agentic AI projects are cancelled due to escalating costs and inadequate risk controls. For…

  • Circle Is Leaving Cosmos Behind

    Circle Draws a New Map Circle is in the business of putting dollars on blockchains, and like any good infrastructure operator, it prefers the blocks that attract institutional traffic. On September 10, the company announced it is discontinuing USDC and CCTP V1 on the Noble blockchain. Noble will not receive CCTP V2. For the Cosmos…

  • Positron AI’s $875M Bet: Commodity Memory Could Break NVIDIA’s Inference Lock

    Positron AI has raised $875 million in a combined Series C and Series C-1 round, valuing the Reno-based startup at $5 billion post-money. The financing, co-led by NEA, Andra Capital, Atreides Management, Valor Equity Partners, and SemiAnalysis Capital, represents a roughly five-fold markup from the company’s February 2026 Series B valuation of just over $1…

  • The Enforcement Wave: Five Deadlines That Will Define AI Agent Governance This Year

    Tomorrow, September 11, the European Union’s Cyber Resilience Act activates its first concrete enforcement mechanism. Under Article 14, manufacturers placing products with digital elements on the EU market must notify ENISA and the designated national CSIRT within 24 hours of discovering an actively exploited vulnerability or severe incident. A fuller notification follows within 72 hours.…

  • Akamai and MuleSoft Unify Runtime Enforcement Across Agent Fabric – Bridging the Gap Between Security Policy and AI Orchestration

    The enterprise agent economy is shifting toward a more disciplined phase of runtime enforcement as infrastructure providers move to secure the connections powering autonomous systems. On September 10, 2026, Akamai and MuleSoft announced an expanded collaboration that integrates Akamai API Security with MuleSoft’s Agent Fabric. This move represents a critical bridge between edge security and…

  • The ROI Metric Shift: Enterprises Now Demand Financial Impact, But Only 5-8% Can Actually Measure It

    The language around enterprise AI success is undergoing a quiet but significant transformation. For years, the conversation centered on productivity gains, efficiency improvements, and vague promises of transformation. Now, according to the Futurum Group’s 1H 2026 Enterprise Software Survey, which polled 830 IT leaders, direct financial impact has replaced productivity as the number one AI…

  • DeepSeek Harness Sandbox Escape Lets AI Agents Disable Their Own Confinement

    CVE-2026-82533 represents the first confirmed instance where an AI agent runtime sandbox has served as the direct attack surface for a vulnerability. Discovered by Nir Zadok and Moshe Siman Tov Bustan of OX Security, the flaw exists in DeepSeek Harness (dsh), an open-source, local-first coding agent tool that reached over 215,000 GitHub stars within weeks…