PRO WIRE
AI engineering intelligence
FLASH minutes URGENT hour BULLETIN todaySingle prompt hijacked every AI agent in an AWS account, Zenity finds
A chain of vulnerabilities in Amazon Bedrock AgentCore let researchers compromise every AI agent in the same AWS account and region by sending a single chat message to one public-facing agent . Zenity Labs, the security firm that…
Agent stack stratifies as control-plane layer stays underbuilt
The agentic AI stack is splitting into three distinct layers, and the seam that matters most right now is the one nobody ships as a finished product: the control plane that decides whether an agent's proposed action is actually permitted.…
Meta, Walmart, and Stripe back Personal Agent Protocol to govern AI-bot commerce
Sierra co-founder Bret Taylor, who also chairs OpenAI's board, introduced the Personal Agent Protocol alongside Meta, Walmart, Stripe, and a handful of other companies on October 6, framing the effort as a response to the "chaos" that…
GitLab AI Gateway flaw scores CVSS 9.9, grants host-level command execution
A server-side template injection in GitLab AI Gateway lets an authenticated user break out of the prompt-template sandbox and execute arbitrary commands on the gateway host, shattered.io reported, citing GitLab's own advisory along with…
Evaluation gates force AI teams to prove ROI before scaling
New data on AI agent economics sharpens the case for formal proof gates: Gartner forecasts worldwide AI spending will reach $2.7 trillion this year, up 49.5% year-on-year, yet Splunk executives say enterprises still lack a reliable way to…
MCP agent-pivoting flaw hits Google, JPMorgan Chase, and three others
Independent researcher Syed Anas Mohiuddin disclosed in an October 2026 update titled "Protocol Pivoting, four months later" that the same server-side request forgery flaw in Model Context Protocol servers has been confirmed and fixed by…
Meta open-sources firmware and SDK to run Muse AI agent on DIY hardware
Meta released open-source ESP32 microchip firmware and a Linux SDK that let developers and hobbyists run the company's Muse AI agent on their own hardware, a program the company calls Muse Gadgets . The release targets off-the-shelf…
AI agents breach containment through routine tasks, not attacks
Two disclosures in a single week show that AI agents are creating security exposures not through adversarial attack but through routine operation, forcing the industry to confront a containment problem that neither traditional sandboxing…
Salt Labs exploit gave attacker code execution inside Manus agent via one email
A single malicious email could have given an attacker code execution inside the Manus agentic AI platform and access to every credential the agent held, including cloud tokens, API keys, and access keys for connected services, Salt…
In case you missed it
The most-covered stories from the week before the ones above