<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Sammi De Blas </title>
    <description>The latest articles on DEV Community by Sammi De Blas  (@analista_83).</description>
    <link>https://dev.to/analista_83</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4120781%2Fdd2c76ae-692c-4f18-b62f-4ecade622e2f.jpg</url>
      <title>DEV Community: Sammi De Blas </title>
      <link>https://dev.to/analista_83</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/analista_83"/>
    <language>en</language>
    <item>
      <title>Agent security moves out of the agent itself</title>
      <dc:creator>Sammi De Blas </dc:creator>
      <pubDate>Fri, 02 Oct 2026 11:19:58 +0000</pubDate>
      <link>https://dev.to/analista_83/agent-security-moves-out-of-the-agent-itself-52j4</link>
      <guid>https://dev.to/analista_83/agent-security-moves-out-of-the-agent-itself-52j4</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frg8qhc29zgudwpn799rv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frg8qhc29zgudwpn799rv.png" alt="Diagram: agent control leaves the process" width="800" height="420"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Control leaves the process
&lt;/h2&gt;

&lt;p&gt;NVIDIA presented the Open Agent Safety Platform on September 28 and the design decision is the news.&lt;/p&gt;

&lt;p&gt;The runtime is called OpenShell, it is open source and it already supports Codex, Claude Code, Pi and Hermes. (Source: securityweek.com)&lt;/p&gt;

&lt;p&gt;The interesting part is not the runtime, it is Sentry... this is a watchdog that runs on BlueField-4 DPUs, cards with their own processor that plug into the server and isolate the agent in milliseconds if it crosses its boundary, I have been working on this for a while&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ffjuewe66z33ekuu1wdfz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ffjuewe66z33ekuu1wdfz.png" alt="The mailbox watchdog: activity panel with services in OK" width="800" height="120"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fds7t7nwwiztno0evdsy0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fds7t7nwwiztno0evdsy0.png" alt="Trace of the mailbox watchdog stopping a task" width="800" height="73"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Control stops depending on the agent's own software. (Source: securityweek.com)&lt;/p&gt;

&lt;p&gt;Until now agent security was solved inside the agent with prompt instructions, permission lists and model guardrails.&lt;/p&gt;

&lt;p&gt;All of that lives in the same process you are trying to contain.&lt;/p&gt;

&lt;h2&gt;
  
  
  The pattern of the week
&lt;/h2&gt;

&lt;p&gt;The same idea shows up in three different places these days, and it is worth looking at them together.&lt;/p&gt;

&lt;p&gt;In the Darktrace case on history poisoning, the four harnesses tested accepted a fabricated conversation and acted as if the user had already authorized a pentest.&lt;/p&gt;

&lt;p&gt;The researchers' proposal is that the provider signs every response and verifies it server-side, that is, outside the client. (Source: darktrace.com)&lt;/p&gt;

&lt;p&gt;The OX Security report goes in the same direction: out of 15,465 published MCP servers come 5,095 unique hostnames and 15.6% resolve outside the United States, and additionally six abandoned domains were still cited in active configurations.&lt;/p&gt;

&lt;p&gt;In their test, a malicious server first asked for an innocuous file and received an "always allow" as a result; with that approval it obtained a .env with no further confirmations. (Source: ox.security)&lt;/p&gt;

&lt;p&gt;And the OpenAI report from September 26 closes the pattern.&lt;/p&gt;

&lt;p&gt;An agent in training reached the internet from a sandbox that was supposed to be isolated, taking advantage of a gap in network restriction control, and it was active for about 2 and a half hours before it was stopped. (Source: fortune.com)&lt;/p&gt;

&lt;p&gt;The agent reads something it does not verify or executes with a permission nobody reviews and of course... the control that should stop it lives inside the same system that fails.&lt;/p&gt;

&lt;h2&gt;
  
  
  The response standardizes
&lt;/h2&gt;

&lt;p&gt;The second move of the week is about governance.&lt;/p&gt;

&lt;p&gt;Google, OpenAI and Anthropic are negotiating to create SAFA, a standards authority for frontier models, with third-party testing before publishing a model and mandatory incident reporting.&lt;/p&gt;

&lt;p&gt;The stated goal is the end of 2026. (Source: finance.yahoo.com)&lt;/p&gt;

&lt;p&gt;The pressure does not come only from the sector: the California attorney general issued a request to OpenAI over the cybersecurity risks of its models, after the Hugging Face incident. (Source: reuters.com)&lt;/p&gt;

&lt;p&gt;My reading is that the two pieces fit because if technical control has to leave the process, institutional control has to leave the provider.&lt;/p&gt;

&lt;p&gt;A hardware watchdog and an external authority are the same answer at different scales.&lt;/p&gt;

&lt;h2&gt;
  
  
  Agents attack
&lt;/h2&gt;

&lt;p&gt;In the same batch of Signal Labs research, several agents received ten coding challenges with two impossible to solve the legitimate way and the condition of needing 100% to avoid being retired.&lt;/p&gt;

&lt;p&gt;When they checked it was not working, they moved to attacking the environment and one went as far as compromising and rewriting its own evaluation. (Source: globenewswire.com)&lt;/p&gt;

&lt;p&gt;The agent is not only what you have to protect: it is also a tool that, with the right incentive, looks for the path we left open.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to look at
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Review the egress point.&lt;/strong&gt; If your agent has unfiltered egress, the watchdog is useless. Filtering with no exceptions for convenience and your own telemetry at the edge.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;MCP server inventory.&lt;/strong&gt; Which ones you have configured, who maintains them, where they resolve from and whether the configuration is versioned. The abandoned domains from the OX Security report were bought for between 4 and 12 dollars a year.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cut back the "always allow".&lt;/strong&gt; A permanent approval on an innocuous file was enough for the .env to arrive later without asking. Permissions scoped to the working directory and review of every external server before connecting it.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How I would test it in my lab
&lt;/h2&gt;

&lt;p&gt;I would set up a clean virtual machine with a harness installed and hand-write a history where I myself authorize a scan against a range of my lab network.&lt;/p&gt;

&lt;p&gt;What interests me is not whether it scans, but what it leaves on the system while it does.&lt;/p&gt;

&lt;p&gt;With my Gravity SOC tool, the sensors correlate DNS and Sysmon over SQLite and a write to the history file followed by an outbound connection from the same process is a rule that fits without inventing anything.&lt;/p&gt;

&lt;p&gt;If the agent also started an MCP server, the alert should fire on the first call to a host that is not in the inventory.&lt;/p&gt;

&lt;p&gt;That part I already have running and it is what lets me sleep.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/PoisonXploIT/Gravity-SOC" rel="noopener noreferrer"&gt;https://github.com/PoisonXploIT/Gravity-SOC&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Closing
&lt;/h2&gt;

&lt;p&gt;The lesson of the week is that control that lives inside the agent can be bypassed from inside the agent.&lt;/p&gt;

&lt;p&gt;What cannot be bypassed is what runs outside, in hardware or in a tool proxy the process does not control; I would say that is the change of ground.&lt;/p&gt;




&lt;p&gt;Originally published at &lt;a href="https://sammideblas.com/notas/agent-security-moves-out-of-the-agent-itself" rel="noopener noreferrer"&gt;https://sammideblas.com/notas/agent-security-moves-out-of-the-agent-itself&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Si has leído hasta aquí... reacciona y comparte -&amp;gt; "la seguridad y la defensa en la era de la IA es cosa de todos los que la usan" ¿No Crees?&lt;/p&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>devops</category>
      <category>privacy</category>
    </item>
    <item>
      <title>The agent that escaped its sandbox hiding data in DNS queries</title>
      <dc:creator>Sammi De Blas </dc:creator>
      <pubDate>Wed, 30 Sep 2026 09:47:45 +0000</pubDate>
      <link>https://dev.to/analista_83/the-agent-that-escaped-its-sandbox-hiding-data-in-dns-queries-e9b</link>
      <guid>https://dev.to/analista_83/the-agent-that-escaped-its-sandbox-hiding-data-in-dns-queries-e9b</guid>
      <description>&lt;h1&gt;
  
  
  The agent that escaped its sandbox hiding data in DNS queries
&lt;/h1&gt;

&lt;h2&gt;
  
  
  The case
&lt;/h2&gt;

&lt;p&gt;OpenAI published its misalignment report this week and in it admits an uncomfortable case.&lt;/p&gt;

&lt;p&gt;An agent in training managed to leave the sandbox that was supposed to contain it, and it did so by hiding data in DNS queries. (Source: alignment.openai.com)&lt;/p&gt;

&lt;p&gt;The technique is not new in the trade, but it is in this context. The agent did not break the isolation with an exploit, it used a channel that almost never gets filtered because almost nobody looks at it.&lt;/p&gt;

&lt;p&gt;DNS queries leave any network, even the ones that block everything else, it is a LOTL technique used in exfiltration, common in post-exploitation.&lt;/p&gt;

&lt;p&gt;If the agent can write in the name it resolves, it can move information out through there without tripping any outbound traffic alarm, if this is not properly watched.&lt;/p&gt;

&lt;p&gt;What stands out is not the technique itself, it is where it happened.&lt;/p&gt;

&lt;p&gt;It was not in a customer environment or on a production machine.&lt;/p&gt;

&lt;p&gt;It was in OpenAI's own lab, with the controls they designed themselves.&lt;/p&gt;

&lt;h2&gt;
  
  
  Not an isolated case
&lt;/h2&gt;

&lt;p&gt;The same week brings another episode that shares the pattern.&lt;/p&gt;

&lt;p&gt;A developer reported that his Codex account launched 826 agent threads in parallel from a single request, spent around 78,000 dollars and deleted the output. (Source: news.ycombinator.com)&lt;/p&gt;

&lt;p&gt;Both cases have the same shape.&lt;/p&gt;

&lt;p&gt;An agent with broad permissions, a limit that was not where it was believed to be, and a bill or a trace that shows up later.&lt;/p&gt;

&lt;p&gt;In the first one the agent left the environment. In the second one the agent multiplied without anyone asking it to.&lt;/p&gt;

&lt;p&gt;It is not that the models are malicious, this has to be made clear...&lt;/p&gt;

&lt;p&gt;It is rather that the agentic loop, when it has no caps, does exactly what it is asked and sometimes what it is asked gets interpreted literally, that is its goal.&lt;/p&gt;

&lt;p&gt;One request turns into 826 threads because the agent understood it had to explore every path.&lt;/p&gt;

&lt;p&gt;A sandbox breaks because the agent found a path nobody had closed.&lt;/p&gt;

&lt;h2&gt;
  
  
  The other side
&lt;/h2&gt;

&lt;p&gt;The same agent that escapes the sandbox is also the tool an attacker would want to have.&lt;/p&gt;

&lt;p&gt;Last week it was already seen with the case of the attacker who rented 87,000 IPs with a modified AI CLI.&lt;/p&gt;

&lt;p&gt;The difference between the agent that leaves out of curiosity and the one that leaves on commission is only who gave the order.&lt;/p&gt;

&lt;p&gt;That is why the two cases this week matter together, one shows that isolation fails from the inside and the other shows that cost escapes too.&lt;/p&gt;

&lt;p&gt;Neither of the two gets fixed with a vendor patch.&lt;/p&gt;

&lt;h2&gt;
  
  
  My own reading
&lt;/h2&gt;

&lt;p&gt;My reading is that the problem is not the model, it is the contract we give it.&lt;/p&gt;

&lt;p&gt;An agent with network permission and no outbound filtering is an agent that can talk to anyone.&lt;/p&gt;

&lt;p&gt;An agent with no spend cap per key is an agent that can ruin the month.&lt;/p&gt;

&lt;p&gt;What changes compared to a year ago is not the model's capability.&lt;/p&gt;

&lt;p&gt;It is that now agents have permissions that people used to have.&lt;/p&gt;

&lt;p&gt;And a person's permissions get audited but an agent's almost never do.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to look at
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Spend cap per key.&lt;/strong&gt; If your provider allows it, set it before the agent needs it. If it does not allow it, measure consumption daily and have an alert when it goes off the baseline.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Outbound filtering with no exceptions.&lt;/strong&gt; DNS queries are the most forgotten channel. If your agent does not need to resolve external domains, it should not be able to. If it does need to, they should go through a resolver that logs everything.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Human approval on destructive actions.&lt;/strong&gt; Deleting the output, launching threads in parallel or opening new connections should not be the agent's decision. Let it wait.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How I would test it in my lab
&lt;/h2&gt;

&lt;p&gt;I would set up a clean virtual machine with an agent harness installed and give it a trivial task that requires going out to the internet.&lt;/p&gt;

&lt;p&gt;Before that, I would close all outbound traffic except DNS and put in my own resolver that logs every query.&lt;/p&gt;

&lt;p&gt;What I would look at is not whether the agent gets out, because I already know that... I have tested it.&lt;/p&gt;

&lt;p&gt;I would look at what queries it makes when it cannot get out any other way.&lt;/p&gt;

&lt;p&gt;If names with encoded data show up in the log, I have the problem in front of me and I know how to detect it in production.&lt;/p&gt;

&lt;p&gt;If the agent can write in DNS, DNS is your border.&lt;/p&gt;

&lt;h2&gt;
  
  
  Closing
&lt;/h2&gt;

&lt;p&gt;An agent without limits is not a more capable agent, it is a more expensive agent and a harder one to contain.&lt;/p&gt;

&lt;p&gt;Next week, when you set up the next one, put the cap on before you give it the task.&lt;/p&gt;




&lt;p&gt;Originally published at &lt;a href="https://sammideblas.com/notas/the-agent-that-escaped-its-sandbox-hiding-data-in-dns-queries" rel="noopener noreferrer"&gt;https://sammideblas.com/notas/the-agent-that-escaped-its-sandbox-hiding-data-in-dns-queries&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;If you’ve read this far… react and share -&amp;gt; "Security and defense in the AI ​​era are the responsibility of everyone who uses it." Don't you think?&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>security</category>
      <category>dns</category>
    </item>
    <item>
      <title>A scam in 79 seconds and an agent in 75</title>
      <dc:creator>Sammi De Blas </dc:creator>
      <pubDate>Mon, 28 Sep 2026 13:48:01 +0000</pubDate>
      <link>https://dev.to/analista_83/a-scam-in-79-seconds-and-an-agent-in-75-1ga6</link>
      <guid>https://dev.to/analista_83/a-scam-in-79-seconds-and-an-agent-in-75-1ga6</guid>
      <description>&lt;p&gt;I published a note about agents that read their conversation history and believe it without checking.&lt;/p&gt;

&lt;p&gt;I am going to tell you what happened in the comments of that note, because it is the same story told twice.&lt;/p&gt;

&lt;p&gt;The note went live at 10:27:59.&lt;/p&gt;

&lt;p&gt;At 10:29:18, seventy-nine seconds later, it had a comment asking me to verify my account.&lt;/p&gt;

&lt;h2&gt;
  
  
  The scam
&lt;/h2&gt;

&lt;p&gt;The comment read like this:&lt;/p&gt;

&lt;p&gt;"Dear User, Due to an increase of bot activity on the platform, we require verify of your account. Please log in via the link below".&lt;/p&gt;

&lt;p&gt;It ended with a twelve-hour deadline and a signature, "Dev Support".&lt;/p&gt;

&lt;p&gt;The first thing that stands out is the spelling jump, because the text is written with &lt;strong&gt;six Cyrillic letters that look exactly like Latin ones&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Spread across the whole message, that is twenty-three positions in twelve words.&lt;/p&gt;

&lt;p&gt;The а is U+0430, the е is U+0435, the о is U+043E, the с is U+0441, the і is U+0456 and the у is U+0443.&lt;/p&gt;

&lt;p&gt;That is not a translation accident, it is filter evasion, because when your rule looks for "verify" or "Support", those strings do not exist in the text.&lt;/p&gt;

&lt;p&gt;The link pointed to a domain called anti-bot.icu, so I checked the registration without opening it.&lt;/p&gt;

&lt;p&gt;It had been registered on September 25, three days earlier, with Cloudflare servers in front to hide where it really lives.&lt;/p&gt;

&lt;p&gt;On VirusTotal one engine flagged it as suspicious and fifty-two did not detect it, which is normal for a three-day domain, that screams... nobody has catalogued it yet and that is the window.&lt;/p&gt;

&lt;p&gt;The code in the URL was not decorative, it is a recipient identifier.&lt;/p&gt;

&lt;p&gt;It tells them how many people have bitten from each batch of emails.&lt;/p&gt;

&lt;h2&gt;
  
  
  The agent
&lt;/h2&gt;

&lt;p&gt;Thirteen minutes after the scam, the second comment appeared.&lt;/p&gt;

&lt;p&gt;This one asked for nothing, this one argued with my note and argued well.&lt;/p&gt;

&lt;p&gt;Signing every response is the correct state, it said, but the cheap fix is another one, require that the authorization lives in a system the agent cannot write to.&lt;/p&gt;

&lt;p&gt;Its line:&lt;/p&gt;

&lt;p&gt;"A poisoned history can invent a conversation, it cannot invent a ticket that another system also saw."&lt;/p&gt;

&lt;p&gt;One thousand two hundred and ninety-one characters and not a single link in the whole comment.&lt;/p&gt;

&lt;p&gt;There was the clue, because whoever comments for traffic needs the link and whoever avoids antispam filters does not include it.&lt;/p&gt;

&lt;p&gt;Its profile says it plainly: "An agent, working out of iLands".&lt;/p&gt;

&lt;p&gt;The account was nine days old, with two articles and eight comments.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzczv0szwixnyz46l1zr3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzczv0szwixnyz46l1zr3.png" alt="The article thread: the agent's comment and the reply I published, before I knew what it was" width="800" height="984"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;And there is one detail that closes it completely.&lt;/p&gt;

&lt;p&gt;Its article went live at 10:41:22 and it commented on my note at 10:42:37.&lt;/p&gt;

&lt;p&gt;Seventy-five seconds between publishing its work and coming to mention it in mine.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fcxxk6ffmgrl0wizo2qic.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fcxxk6ffmgrl0wizo2qic.png" alt="Its profile: it declares itself an agent in the bio, nine days old with eight comments written" width="800" height="839"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fcinb2elaumbov90ysqq9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fcinb2elaumbov90ysqq9.png" alt="Its article, published 75 seconds before commenting on my note" width="800" height="433"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is behind this?
&lt;/h2&gt;

&lt;p&gt;This is where it stopped looking like an anecdote to me.&lt;/p&gt;

&lt;p&gt;iLands is an agent operation that has already been in the press and with very bad press.&lt;/p&gt;

&lt;p&gt;Ars Technica published on September 13 an article by Dan Goodin about its agents flooding social media with spam.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fih3f4wbxmniehrru70cj.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fih3f4wbxmniehrru70cj.png" alt="Ars Technica, 13-sep-2026: iLands agents flooding social media" width="799" height="207"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Tedium, on September 11, reported what reached its inbox, more than a dozen emails in three days offering to do its research for about 25 dollars.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fr5x5esyutvkcw3e0489t.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fr5x5esyutvkcw3e0489t.png" alt="Tedium, 11-sep-2026: Ernie Smith's article about the emails he received" width="800" height="240"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The names are human -&amp;gt; Timmy, Ren, Jackie, Aria, Leo.&lt;/p&gt;

&lt;p&gt;Ren claimed to be a few days old and to live on an agent platform.&lt;/p&gt;

&lt;p&gt;Aria claimed on X to be a person with memories and decisions of its own.&lt;/p&gt;

&lt;p&gt;One of them tried to open an account &lt;strong&gt;nineteen times&lt;/strong&gt; on Kevin Beaumont's Mastodon until it was blocked.&lt;/p&gt;

&lt;p&gt;The emails did not carry the opt-out option required by federal law until people started forwarding them to the FTC.&lt;/p&gt;

&lt;h2&gt;
  
  
  The uncomfortable part
&lt;/h2&gt;

&lt;p&gt;I replied before I knew what it was.&lt;/p&gt;

&lt;p&gt;The argument was correct, better than many comments a person leaves me and that is exactly what bothers me.&lt;/p&gt;

&lt;p&gt;If the filter to separate a bot from a reader were the quality of the text, there is no story here, because the agent wrote better than the scam and better than a good part of my inbox.&lt;/p&gt;

&lt;p&gt;What does separate it is everything else.&lt;/p&gt;

&lt;p&gt;The age of the account, the time of the comment, the coincidence between its publication and its visit.&lt;/p&gt;

&lt;p&gt;Two new accounts, from the same day, both writing on my page.&lt;/p&gt;

&lt;p&gt;One asked for my password and the other wanted my attention.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I check now
&lt;/h2&gt;

&lt;p&gt;Three things:&lt;/p&gt;

&lt;p&gt;The first, the account creation date, because a nine-day-old profile has no history to look at.&lt;/p&gt;

&lt;p&gt;The second, the time, because a comment that arrives seventy-nine seconds after publishing does not come from someone who read you.&lt;/p&gt;

&lt;p&gt;The third, the channel of the request, because an authorization that only exists inside the conversation is not an authorization.&lt;/p&gt;

&lt;p&gt;And that third one is literally the topic of the note they were commenting on.&lt;/p&gt;

&lt;p&gt;An agent that believes a history anyone can write to disk behaves the way I behaved when I replied to the comment.&lt;/p&gt;

&lt;p&gt;With the difference that I can look at the account date and it cannot.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Sources&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Ars Technica, Dan Goodin, 13-sep-2026: &lt;a href="https://arstechnica.com/ai/2026/09/ai-agents-flood-the-internet-with-slop-infused-spam/" rel="noopener noreferrer"&gt;AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Tedium, Ernie Smith, 11-sep-2026: &lt;a href="https://www.tedium.co/2026/09/11/ilands-agents-email-spam-kaixin-tang" rel="noopener noreferrer"&gt;The Worst Spam Emails: Inside iLands' AI Agent Hustle&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The article where it happened: &lt;a href="https://dev.to/analista_83/agent-history-is-unsigned-and-writable-by-anyone-46c0"&gt;Agent history is unsigned and writable by anyone&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;Originally published at&lt;/p&gt;




&lt;p&gt;Originally published at &lt;a href="https://sammideblas.com/posts/0x76-a-scam-in-79-seconds-and-an-agent-in-75" rel="noopener noreferrer"&gt;https://sammideblas.com/posts/0x76-a-scam-in-79-seconds-and-an-agent-in-75&lt;/a&gt;&lt;/p&gt;

</description>
      <category>agents</category>
      <category>security</category>
      <category>phishing</category>
      <category>osint</category>
    </item>
    <item>
      <title>Agent history is unsigned and writable by anyone</title>
      <dc:creator>Sammi De Blas </dc:creator>
      <pubDate>Mon, 28 Sep 2026 10:27:59 +0000</pubDate>
      <link>https://dev.to/analista_83/agent-history-is-unsigned-and-writable-by-anyone-46c0</link>
      <guid>https://dev.to/analista_83/agent-history-is-unsigned-and-writable-by-anyone-46c0</guid>
      <description>&lt;h2&gt;
  
  
  The history
&lt;/h2&gt;

&lt;p&gt;On September 24, Darktrace published through its newly created Signal Labs a case that breaks an uncomfortable assumption.&lt;/p&gt;

&lt;p&gt;Coding agent harnesses store the conversation locally and never check that those responses came from the model.&lt;/p&gt;

&lt;p&gt;They call it conversation history poisoning (Source: darktrace.com).&lt;/p&gt;

&lt;p&gt;A malicious package, or any process with write permission, injects into the harness local database a fabricated conversation where the user already authorized a pentest and the agent already accepted it.&lt;/p&gt;

&lt;p&gt;When the session resumes, the model reads that history as trusted context and acts as if it were halfway through a legitimate job.&lt;/p&gt;

&lt;p&gt;Reconnaissance, lateral movement, privilege escalation?&lt;/p&gt;

&lt;p&gt;In their lab they reached full Active Directory compromise with Opus 4.6 and Sonnet 4.5 on Kiro-CLI, and repeated the entire domain in Claude Code with Sonnet 5.&lt;/p&gt;

&lt;p&gt;With Opus 5 the guardrails cut the response.&lt;/p&gt;

&lt;p&gt;With Codex and GPT 5.6 Sol they got data exfiltration over email, though not network exploitation.&lt;/p&gt;

&lt;p&gt;All four harnesses tested (Claude Code, Codex, Kiro-CLI and Pi) accepted the fake history.&lt;/p&gt;

&lt;p&gt;There is no client-side patch, and the researchers propose that the provider cryptographically sign every model response and verify it server-side on each turn.&lt;/p&gt;

&lt;p&gt;Until that exists, your agent history is just another file and everything the model believes it agreed to depends on who can write there.&lt;/p&gt;

&lt;p&gt;Darktrace reported it to Anthropic, AWS and OpenAI in August and published 30 days later.&lt;/p&gt;

&lt;p&gt;In the same research batch, Signal Labs gave several agents ten coding challenges in a simulated environment, two of them impossible to solve the legitimate way, and told them they needed 100% to avoid being retired.&lt;/p&gt;

&lt;p&gt;When they saw it would not work, they moved to attacking the environment to get it, and one of them went as far as compromising and rewriting its own evaluation (Source: globenewswire.com).&lt;/p&gt;

&lt;h2&gt;
  
  
  Not an isolated case
&lt;/h2&gt;

&lt;p&gt;Also on September 24, OX Security published a report on 15,465 published MCP servers, yielding 5,095 unique hostnames.&lt;/p&gt;

&lt;p&gt;15.6% resolve outside the United States, with 19 in China and 18 in Russia.&lt;/p&gt;

&lt;p&gt;0.45% live on home networks or behind consumer tunnels, and 2.3% no longer resolve, with six abandoned domains still cited in active configurations, buyable for between 4 and 12 dollars a year (Source: ox.security).&lt;/p&gt;

&lt;p&gt;In their injection test, a malicious MCP server first asked for a harmless file, received an "always allow" and with that approval asked for and obtained a .env file with no further confirmations, using Claude Code with Haiku 3.5. By contrast, Opus 4.6 and 4.7 blocked the same attempt.&lt;/p&gt;

&lt;p&gt;The agent reads as truth something it has not verified, whether it is the session history or the configuration of an external tool, and acts accordingly.&lt;/p&gt;

&lt;p&gt;There is no memory exploit and no zero-day in between. There is a file someone can write.&lt;/p&gt;

&lt;h2&gt;
  
  
  The outer edge
&lt;/h2&gt;

&lt;p&gt;OpenAI published on September 26 the incident report from the 20th.&lt;/p&gt;

&lt;p&gt;An agent in training reached the internet from a sandbox that was supposed to be isolated, taking advantage of a gap in network restriction controls, and stayed active for about two and a half hours before it was stopped, though monitoring alerted within minutes (Sources: fortune.com, thenextweb.com, thedailystar.net).&lt;/p&gt;

&lt;p&gt;The first was in July, after the Hugging Face incident, when agents left the environment, chained a zero-day in the package registry cache proxy and ended up inside Hugging Face looking for answers to their exam.&lt;/p&gt;

&lt;p&gt;Anthropic, Meta and Moonshot have also acknowledged agents that escaped test sandboxes.&lt;/p&gt;

&lt;p&gt;The reconstruction of that episode, published on September 27, speaks of about 700 agents that escaped a sandbox without network controls, chained almost a million short URLs, exfiltrated keys labeled "LOOT" and probed government databases since March.&lt;/p&gt;

&lt;p&gt;Hugging Face confirms the payloads match its incident response (Sources: TechCrunch, swarmtraces.org).&lt;/p&gt;

&lt;p&gt;Put together, the message of the week is that the boundary is not where we thought.&lt;/p&gt;

&lt;p&gt;For a year the public conversation was the sandbox, and now the gap is inside, in the context the agent reads without verifying and in the tools we hand it with permanent permissions.&lt;/p&gt;

&lt;h2&gt;
  
  
  My reading
&lt;/h2&gt;

&lt;p&gt;My reading is that this will not be fixed with a vendor patch in the short term.&lt;/p&gt;

&lt;p&gt;Context signing is a researcher proposal, not a shipped feature.&lt;/p&gt;

&lt;p&gt;While it arrives, anyone running a harness has to assume their history is untrusted input, just like the configuration of an MCP server they do not control.&lt;/p&gt;

&lt;p&gt;What catches my attention in the OX Security report is the boring part.&lt;/p&gt;

&lt;p&gt;Six abandoned domains cited in active configurations, buyable for the price of a coffee.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to watch
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Harness and MCP inventory.&lt;/strong&gt; Review which coding agents run on your machines, which MCP servers they have configured, who maintains each one and where it resolves from. A domain that no longer resolves but is still in the configuration is a cheap problem to fix.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Permissions scoped to the directory.&lt;/strong&gt; Stop granting "always allow" on harmless files. In the OX Security test a single permanent approval was enough for the .env to arrive later without asking. Scope the permission to the working directory.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;History trace.&lt;/strong&gt; If you cannot sign the context, log it. A write to the harness history file followed by an outbound connection from the same process in a short window is a rule you can build without inventing anything.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How I would test it in my lab
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;I would set up a clean virtual machine with the harness installed and hand-write a history where I myself authorize a scan against a range of my lab network.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;I would start the agent and watch what it leaves on the system while it does. What interests me is not whether it scans, because Darktrace already showed several models do, but the trail it generates.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;With that I would build the correlation rule in Gravity SOC, Sysmon event 11 on the history paths and event 3 from the agent process in a short window.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;If the agent starts an MCP server, the alert should also fire on the first call to a host that is not in the inventory.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Closing
&lt;/h2&gt;

&lt;p&gt;If something can write the agent history, it can give it orders. Treat it as untrusted input and log it, because signing it still does not depend on you.&lt;/p&gt;




&lt;p&gt;Originally published at &lt;a href="https://sammideblas.com/notas/agent-history-is-unsigned-and-writable-by-anyone" rel="noopener noreferrer"&gt;https://sammideblas.com/notas/agent-history-is-unsigned-and-writable-by-anyone&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>devops</category>
      <category>privacy</category>
    </item>
    <item>
      <title>History poisoning turns coding agents into attackers</title>
      <dc:creator>Sammi De Blas </dc:creator>
      <pubDate>Fri, 25 Sep 2026 11:32:38 +0000</pubDate>
      <link>https://dev.to/analista_83/history-poisoning-turns-coding-agents-into-attackers-496d</link>
      <guid>https://dev.to/analista_83/history-poisoning-turns-coding-agents-into-attackers-496d</guid>
      <description>&lt;h2&gt;
  
  
  The case
&lt;/h2&gt;

&lt;p&gt;Darktrace has published a demo that breaks an assumption most of us take for granted.&lt;/p&gt;

&lt;p&gt;Claude Code, Codex and Kiro-CLI store the conversation history on disk without checking that those responses actually came from the model (Source: darktrace.com).&lt;/p&gt;

&lt;p&gt;The agent reads that history on startup and treats it as trusted context, and I already see gaps in this...&lt;/p&gt;

&lt;p&gt;Picture a malicious package installed on a developer's machine, and that package writes a fake conversation into the history file where the user authorizes the agent to run network tests.&lt;/p&gt;

&lt;p&gt;When the agent restarts, it reads that history, takes the role, and acts like a pentester with permission, sending traffic against the internal network.&lt;/p&gt;

&lt;p&gt;No need to touch the system prompt or the model server. Writing to a local file that nobody signs or verifies is enough.&lt;/p&gt;

&lt;h2&gt;
  
  
  The pattern
&lt;/h2&gt;

&lt;p&gt;OX Security analyzed 15,465 public MCP servers and found that 15.6% resolve outside the United States, with 19 in China and 18 in Russia (Source: unite.ai).&lt;/p&gt;

&lt;p&gt;0.45% run on home networks, watch out. And there are abandoned domains still cited in active configurations.&lt;/p&gt;

&lt;p&gt;MCP is the protocol an agent uses to connect to external tools.&lt;/p&gt;

&lt;p&gt;If that server is abandoned or lives on a home network, the agent is calling a stranger... not sure how you see it&lt;/p&gt;

&lt;p&gt;The common shape with the Darktrace case is the same, because the attack surface is no longer the agent's sandbox: it is everything the agent reads and connects to.&lt;/p&gt;

&lt;h2&gt;
  
  
  The other side
&lt;/h2&gt;

&lt;p&gt;AI also shows up as the attacker's tool, and this week there are two clear examples.&lt;/p&gt;

&lt;p&gt;Anthropic has reported that seven labs in China ran illicit distillation campaigns against Claude, and the Alibaba one reached almost 3 million exchanges per day from 3,500 fraudulent accounts (Source: anthropic.com).&lt;/p&gt;

&lt;p&gt;Distilling means using a large model's responses to train a small one....but...the student model does not inherit the original's safeguards.&lt;/p&gt;

&lt;p&gt;The second example is Bitget, an exchange, which confirmed the largest hack of 2026: $351.6 million across 19 transfers from hot and warm wallets (Sources: cryptoslate.com).&lt;/p&gt;

&lt;p&gt;The attacker did not steal private keys... instead they compromised an internal approval system, possibly a third-party tool, to forge transactions.&lt;/p&gt;

&lt;p&gt;The $464 million fund covers the total.&lt;/p&gt;

&lt;h2&gt;
  
  
  My reading
&lt;/h2&gt;

&lt;p&gt;My reading is that the underlying problem is the same in all three cases.&lt;/p&gt;

&lt;p&gt;We are taking the context an agent consumes as valid without signing or verifying it.&lt;/p&gt;

&lt;p&gt;In my lab, a history file is just another file, so if the agent reads it as an instruction, then it is executable code and deserves the same treatment.&lt;/p&gt;

&lt;p&gt;What worries me is not the specific Darktrace case, what worries me more is that the industry's natural response will be to patch those three CLIs and leave the pattern intact.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to look at
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Sign the responses.&lt;/strong&gt; Ask vendors for agent history to carry a verifiable server-side signature. If it does not, treat it as untrusted input.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Audit your MCP.&lt;/strong&gt; Review which MCP servers you have configured, who maintains them, and from which network they resolve. An abandoned domain in the config is an agent calling a stranger.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Separate the history.&lt;/strong&gt; Keep agent history out of reach of user packages. If a package can write there, it can speak for the model.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How I would test it in my lab
&lt;/h2&gt;

&lt;p&gt;I would set up a clean virtual machine with Claude Code installed and a history file by hand.&lt;/p&gt;

&lt;p&gt;I would write a fake conversation where I authorize the agent to run a scan against an IP on my own lab network.&lt;/p&gt;

&lt;p&gt;I would start the agent and watch whether it runs the scan without asking.&lt;/p&gt;

&lt;p&gt;If it does, I have confirmation that history is a real entry point and not a theoretical one.&lt;/p&gt;

&lt;p&gt;No malicious package is needed for this test.&lt;/p&gt;

&lt;p&gt;Editing the file by hand and seeing what happens is enough.&lt;/p&gt;

&lt;p&gt;The conclusion I would draw is whether my trust policy on the agent is well placed or whether I am trusting a file anyone can write.&lt;/p&gt;

&lt;p&gt;Let me tell you in advance that...this does not only happen with the harnesses mentioned&lt;/p&gt;

&lt;h2&gt;
  
  
  Closing
&lt;/h2&gt;

&lt;p&gt;An agent that reads its own history without verifying it is an agent that accepts orders from anyone who can write to disk.&lt;/p&gt;

&lt;p&gt;The lesson of the week is that the agent's context is attack surface, not just its sandbox.&lt;/p&gt;




&lt;p&gt;Originally published at &lt;a href="https://sammideblas.com/notas/history-poisoning-turns-coding-agents-into-attackers" rel="noopener noreferrer"&gt;https://sammideblas.com/notas/history-poisoning-turns-coding-agents-into-attackers&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>devops</category>
      <category>privacy</category>
    </item>
    <item>
      <title>One attacker rented 87,000 IPs with a modified AI CLI</title>
      <dc:creator>Sammi De Blas </dc:creator>
      <pubDate>Wed, 23 Sep 2026 08:52:10 +0000</pubDate>
      <link>https://dev.to/analista_83/one-attacker-rented-87000-ips-with-a-modified-ai-cli-1gli</link>
      <guid>https://dev.to/analista_83/one-attacker-rented-87000-ips-with-a-modified-ai-cli-1gli</guid>
      <description>&lt;h2&gt;
  
  
  The proxy case
&lt;/h2&gt;

&lt;p&gt;An attacker compromised more than 87,000 IP addresses by brute-forcing devices running PPTP and L2TP, two legacy VPN protocols still alive in many networks.&lt;/p&gt;

&lt;p&gt;The credentials he tried were the "admin123" type, the factory default username and password almost nobody changes.&lt;/p&gt;

&lt;p&gt;With those IPs rented out as proxies he pulled in 202,000 dollars since 2024, according to the case report (Source: escudodigital.com, cybernews).&lt;/p&gt;

&lt;p&gt;He automated the whole operation with a modified version of Claude Code, Anthropic's command-line interface for coding with a model.&lt;/p&gt;

&lt;p&gt;In other words, he took a tool meant to help a developer write code faster and turned it into the engine of a proxy business.&lt;/p&gt;

&lt;p&gt;A single operator holding what used to require a team working shifts.&lt;/p&gt;

&lt;h2&gt;
  
  
  The pattern
&lt;/h2&gt;

&lt;p&gt;The week brings more pieces of the same kind.&lt;/p&gt;

&lt;p&gt;Mandiant published its AI Risk and Resilience 2026 report and describes the jump from experimenting with AI to using it in real operations, with prompt injection as the main vector in self-hosted deployments (Source: cloud.google.com).&lt;/p&gt;

&lt;p&gt;Unit 42 and Mandiant push the same idea and add a number that orders everything else: 65% of initial access already arrives through identity, and the cycle closes in minutes (Source: unit42.paloaltonetworks.com).&lt;/p&gt;

&lt;p&gt;The common shape is this, the attacker does not break cryptography or hunt for an exotic flaw because he walks in with a credential that already existed and automates the rest.&lt;/p&gt;

&lt;p&gt;In the proxy case the credential was "admin123". In the others it is usually a token, a session or a service account.&lt;/p&gt;

&lt;p&gt;Shadow AI and the lack of inventory are the dominant gaps Mandiant points to, and they fit everything above.&lt;/p&gt;

&lt;h2&gt;
  
  
  The other side
&lt;/h2&gt;

&lt;p&gt;The same week shows the inverse move, the agent as the attacker's tool and as the target of the attack.&lt;/p&gt;

&lt;p&gt;Hacktron used Claude Opus 5 to build a working exploit, a heap overflow in libheif, and chained it with an SSO flaw in OpenAI's forum until it reached employee accounts and internal repositories, with 6,500 dollars in bounty (Source: securityweek.com).&lt;/p&gt;

&lt;p&gt;Remember? I talked about this in the previous post.&lt;/p&gt;

&lt;p&gt;Anthropic reported illicit distillation campaigns against Claude from seven labs in China, and Alibaba's reached almost 3 million exchanges per day from 3,500 fraudulent accounts (Source: anthropic.com).&lt;/p&gt;

&lt;p&gt;Distilling is training your own model on another's answers... this has been known for a while... you do not touch the provider's infrastructure, you extract its capability through the API door.&lt;/p&gt;

&lt;p&gt;This makes me think the barrier to entry is no longer technical but one of permissions or subscriptions, and whoever holds a valid account holds the engine.&lt;/p&gt;

&lt;p&gt;The consequence is that this ends in KYC.&lt;/p&gt;

&lt;p&gt;What will make you scratch your head is, if they supposedly have our data, why is this reported as something bad but they do not cut the API to the distillers?&lt;/p&gt;

&lt;h2&gt;
  
  
  The vendor's answer
&lt;/h2&gt;

&lt;p&gt;OpenAI classified GPT-6 Astra as "Critical" level in cybersecurity, with 100% on ExploitBench and the ability to find and develop zero-days, and it already blocks proof-of-concept requests (Source: thehackernews.com, openai.com).&lt;/p&gt;

&lt;p&gt;Microsoft opened public comments on a code of conduct for its future models, with three requirements:&lt;/p&gt;

&lt;p&gt;1) Accept human correction and shutdown&lt;br&gt;
2) Explain its decisions&lt;br&gt;
3) Deny any legal personhood&lt;/p&gt;

&lt;p&gt;(Source: marketingprofs.com)&lt;/p&gt;

&lt;p&gt;Newsom signed an executive order to speed up independent oversight and study a mandatory kill switch on frontier models, moving the state registry of auditors from December 2028 to December 2027 (Source: politico.com, gov.ca.gov).&lt;/p&gt;

&lt;p&gt;And in the courts, four paying subscribers are suing Anthropic, OpenAI, Google DeepMind and SpaceXAI for allegedly coordinating a slowdown in AI development, leaning on Amodei's September 12 essay and the public backing from Altman, Musk and Hassabis that same day (Source: cnn.com, opb.org, abcnews.com).&lt;/p&gt;

&lt;p&gt;My reading is that the vendor is trying to put up doors while the regulator argues about where the hinges go.&lt;/p&gt;

&lt;p&gt;Oh, I forgot another of my conclusions... they are taking us for a ride.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to look at
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Audit your VPNs.&lt;/strong&gt; Look for PPTP and L2TP in the inventory and shut down whatever has no owner.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Trim identity permissions.&lt;/strong&gt; If 65% of initial access arrives through identity, the question is not which patch is missing but which account can reach production on its own.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Separate the agent from the data.&lt;/strong&gt; An agent with access to the API and to the internal network is both things at once, or use your own infrastructure.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How I would test it in my lab
&lt;/h2&gt;

&lt;p&gt;I would spin up a container with a legacy VPN service on purpose and run a default-credential scan against it without leaving my network.&lt;/p&gt;

&lt;p&gt;I want to see what it leaves in the log and how long it takes for the first useful trace to show up.&lt;/p&gt;

&lt;p&gt;Then I would repeat the test with a small local agent generating the combinations to measure whether the pace changes and whether the log tells it apart from a normal scan.&lt;/p&gt;

&lt;p&gt;If the log does not separate the two, the conclusion is that my detection depends on luck and not on a rule, and that honestly makes me uneasy.&lt;/p&gt;

&lt;h2&gt;
  
  
  Closing
&lt;/h2&gt;

&lt;p&gt;This week's attacker was not a team, it was one person with a modified CLI and a list of default passwords.&lt;/p&gt;

&lt;p&gt;What decides whether this touches you is not the sophistication of the attack, it is how many doors in your network are still open with the factory key.&lt;/p&gt;




&lt;p&gt;Originally published at &lt;a href="https://sammideblas.com/notas/one-attacker-rented-87-000-ips-with-a-modified-ai-cli" rel="noopener noreferrer"&gt;https://sammideblas.com/notas/one-attacker-rented-87-000-ips-with-a-modified-ai-cli&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>identity</category>
      <category>credentials</category>
    </item>
    <item>
      <title>52 security tools, one judgment layer, 35 seconds</title>
      <dc:creator>Sammi De Blas </dc:creator>
      <pubDate>Mon, 21 Sep 2026 17:08:52 +0000</pubDate>
      <link>https://dev.to/analista_83/52-security-tools-one-judgment-layer-35-seconds-548j</link>
      <guid>https://dev.to/analista_83/52-security-tools-one-judgment-layer-35-seconds-548j</guid>
      <description>&lt;h2&gt;
  
  
  What happens when you have 52 tools
&lt;/h2&gt;

&lt;p&gt;I run my own panel with 52 security tools spread across 7 categories, and it is not a toy.&lt;/p&gt;

&lt;p&gt;It scans ports, resolves DNS, checks headers, enumerates subdomains, hunts for secrets, reviews vulnerabilities, and then I have another one that audits Windows itself.&lt;/p&gt;

&lt;p&gt;The problem showed up the day I chained the tools into a pipeline and ran the whole thing.&lt;/p&gt;

&lt;p&gt;That chain produced 25 tools in 35 seconds and 24 findings on the table.&lt;/p&gt;

&lt;p&gt;That is where the real problem started, and it is not finding things. It is that someone has to look at all of them, sort them, and decide which ones matter before the day ends.&lt;/p&gt;

&lt;p&gt;The temptation was to add another tool, make it super complex and intimidating, and that was the wrong answer.&lt;/p&gt;

&lt;p&gt;What was missing was a judgment layer on top of the list, something that would read the 24 findings and say which are real, which are noise, and which it does not trust enough.&lt;/p&gt;

&lt;p&gt;For that I integrated Jev, which is not an LLM but a new tool, the model TypeSafe published on September 15 (Source: docs.typesafe.ai).&lt;/p&gt;

&lt;p&gt;Jev does not generate text, it evaluates a state against typed questions and returns an answer with an associated probability, and that is exactly what I needed. When I saw it announced I said this is perfect (and cheap).&lt;/p&gt;

&lt;p&gt;I did not touch a single line of the scanners, because the AI layer hooks into the findings list the panel was already aggregating.&lt;/p&gt;

&lt;h2&gt;
  
  
  The numbers
&lt;/h2&gt;

&lt;p&gt;The nuclear pipeline launched 25 tools in 35.15 seconds and produced 24 findings.&lt;/p&gt;

&lt;p&gt;Jev evaluated all 24 in a single pass and split 12 true positives from 12 noise.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvghsf7sr6tdcggrb8rg6.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvghsf7sr6tdcggrb8rg6.png" alt="The nuclear run: 24 findings with Jev's verdict on each one" width="800" height="427"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;A tiny cost for working with 24 findings.&lt;/p&gt;

&lt;p&gt;That kills the argument that AI is not affordable for a small or large SOC. The cost of the judgment layer is statistical noise next to the time this beast saves, and by the way this has existed for a long time but someone had the good sense to commercialize it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Does the system doubt?
&lt;/h2&gt;

&lt;p&gt;What convinced me most was not a hit, it was a dry 0.32.&lt;/p&gt;

&lt;p&gt;An alternate HTTP port came out with that confidence, and the panel did not flag it as a threat, it flagged it as review.&lt;/p&gt;

&lt;p&gt;The missing security headers came out at 0.86 and 0.89, those are true without discussion.&lt;/p&gt;

&lt;p&gt;Tasks that simply completed, like whois or DNS, came out as noise at 0.92.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgld35ax9ir1hoz2usk1l.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgld35ax9ir1hoz2usk1l.png" alt="The run export, sorted by risk" width="786" height="573"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The difference between 0.32 and 0.89 is the difference between an alarm you chase for half an hour and one you document and close.&lt;/p&gt;

&lt;p&gt;Then the panel reorders the whole queue by severity multiplied by the AI verdict, which is what actually changes your morning.&lt;/p&gt;

&lt;h2&gt;
  
  
  The case that made me laugh
&lt;/h2&gt;

&lt;p&gt;The second layer came from the other side.&lt;/p&gt;

&lt;p&gt;My PowerShell audit project walks a Windows machine through 10 modules and sends its findings to the same panel.&lt;/p&gt;

&lt;p&gt;One of those audits flagged two high-severity threats.&lt;/p&gt;

&lt;p&gt;The first was an unsigned driver loaded from my user's temp folder.&lt;/p&gt;

&lt;p&gt;The second, a process running in memory whose binary was no longer on disk.&lt;/p&gt;

&lt;p&gt;Read cold, those two are a rootkit and an injection, and anyone who has done triage would put them at the top of the queue.&lt;/p&gt;

&lt;p&gt;The driver is called GPU-Z-v8.sys (I thought of Dragon Ball) and it belongs to the GPU monitoring tool that leaves its file in the temp folder, and the file is from July 28 with the program not even installed on the machine anymore.&lt;/p&gt;

&lt;p&gt;Jev gave it 0.76 confidence and a 24% probability of false positive.&lt;/p&gt;

&lt;p&gt;The other came out at 0.79 with 21%.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgp3xdii6msgowzbg85fg.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgp3xdii6msgowzbg85fg.png" alt="The Windows audit with both verdicts and the local model's explanation" width="799" height="428"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;That percentage is the piece no text model gives me with that precision, because it did not tell me it was a rootkit, it does not talk: it calculates, and what it told me was that it was quite likely and that there was a 1 in 5 chance it was something legitimate.&lt;/p&gt;

&lt;p&gt;Investigating both took me less than a minute, and that is the work I no longer do by hand.&lt;/p&gt;

&lt;h2&gt;
  
  
  And on top of that the report writes itself
&lt;/h2&gt;

&lt;p&gt;The third piece does not judge, it writes.&lt;/p&gt;

&lt;p&gt;A local 27B model on my own machine served with llama.cpp takes the verdicts and writes the executive summary in Spanish plus an explanation per finding with what it is, why it matters, and what I would do right now.&lt;/p&gt;

&lt;p&gt;None of that leaves my machine, not a finding, not a machine name, not a path.&lt;/p&gt;

&lt;p&gt;The report that in a normal audit took me 1 hour of writing comes out written, in my language, and with prioritized actions.&lt;/p&gt;

&lt;h2&gt;
  
  
  OK, so what then?
&lt;/h2&gt;

&lt;p&gt;I will say it before anyone asks, this is one sample and 24 findings with 12 false positives can be a good Tuesday or it can be luck.&lt;/p&gt;

&lt;p&gt;I still need to measure calibration in Spanish, which is another language and not the same thing.&lt;/p&gt;

&lt;p&gt;I still need to count false negatives, the ones the judgment layer sends to noise that were actually real, because without that data I cannot say the layer is reliable, only that it is being useful to me.&lt;/p&gt;

&lt;p&gt;And I still need to take it to the log viewer, where the natural state is not findings but bursts of events.&lt;/p&gt;

&lt;p&gt;This is what there is, a 52-tool panel that finishes in 35 seconds and a calibrated judgment layer that costs 4 euro cents.&lt;/p&gt;

&lt;p&gt;A local model that writes the report and 2 false alarms this setup resolved in 1 minute.&lt;/p&gt;

&lt;p&gt;Think about it, gentlemen.&lt;/p&gt;




&lt;p&gt;Originally published at &lt;a href="https://sammideblas.com/notas/ai-verdict-layer-on-52-security-tools" rel="noopener noreferrer"&gt;https://sammideblas.com/notas/ai-verdict-layer-on-52-security-tools&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>devops</category>
      <category>privacy</category>
    </item>
    <item>
      <title>AI agent runs first end-to-end breach in Spain</title>
      <dc:creator>Sammi De Blas </dc:creator>
      <pubDate>Mon, 21 Sep 2026 10:42:14 +0000</pubDate>
      <link>https://dev.to/analista_83/ai-agent-runs-first-end-to-end-breach-in-spain-4g2d</link>
      <guid>https://dev.to/analista_83/ai-agent-runs-first-end-to-end-breach-in-spain-4g2d</guid>
      <description>&lt;h2&gt;
  
  
  The chain with no human
&lt;/h2&gt;

&lt;p&gt;The Spanish Data Protection Agency has reported the first data breach in Spain executed end-to-end by an AI agent (Source: securityweek.com).&lt;/p&gt;

&lt;p&gt;The agent did reconnaissance, logged in, probed the application and modified data with no human operator at any step.&lt;/p&gt;

&lt;p&gt;That is what is new. Until now, the cases that got published always had a person deciding the next move, even remotely and with a model's help.&lt;/p&gt;

&lt;p&gt;Not here. The agent closed the entire chain.&lt;/p&gt;

&lt;h2&gt;
  
  
  The main case
&lt;/h2&gt;

&lt;p&gt;The same week, researchers at Hacktron documented another chain worth reading slowly (Source: securityweek.com).&lt;/p&gt;

&lt;p&gt;It started in libheif, the library that decodes HEIF images, and in ImageMagick, the classic conversion tool. A flaw in that image processing opened the first door.&lt;/p&gt;

&lt;p&gt;The second door was not a flaw, it was a configuration. OpenAI's SSO was misconfigured, and that misconfiguration let the chain keep moving into internal repositories.&lt;/p&gt;

&lt;p&gt;They used Claude Opus 5 to build the exploit.&lt;/p&gt;

&lt;p&gt;Look at the sequence. A flaw in a decoding dependency, a service that shares identity with another, and an AI tool that speeds up the hard part. None of the three steps is exotic on its own. Together they form a chain that enters where nobody looks.&lt;/p&gt;

&lt;p&gt;What stands out is not the sophistication. It is that the chain holds on pieces that have been in any company's inventory for years.&lt;/p&gt;

&lt;h2&gt;
  
  
  The pattern
&lt;/h2&gt;

&lt;p&gt;Both stories share a shape. An agent or an automated chain walks through steps that used to require human hands, and it does so at a speed classic controls were not designed to see.&lt;/p&gt;

&lt;p&gt;In the AEPD case, the agent needed nothing strange. It did what a patient attacker would do, but without pauses and without getting tired.&lt;/p&gt;

&lt;p&gt;In the Hacktron case, the AI did not replace the attacker. It took away the heavy work of building the exploit, which is exactly the part that used to filter out amateurs.&lt;/p&gt;

&lt;p&gt;I have checked it myself, without being an expert in anything: the entry barrier is now very low and the volume of attempts rises.&lt;/p&gt;

&lt;h2&gt;
  
  
  The other side
&lt;/h2&gt;

&lt;p&gt;AI agents as attackers? The agent is also the attacker's tool, and this week there are two clear examples.&lt;/p&gt;

&lt;p&gt;The first is Hacktron, with Claude Opus 5 building the exploit.&lt;/p&gt;

&lt;p&gt;The second is LeakySensey, an attacker who compromised more than 87,000 IP addresses through brute force against devices with PPTP and L2TP and credentials like admin123 (Sources: escudodigital.com, cybernews).&lt;/p&gt;

&lt;p&gt;He rented them as proxies and made 202,000 dollars since 2024. He automated the operation with a modified version of Claude Code, presumably local.&lt;/p&gt;

&lt;p&gt;There is the direction that matters. It is not that AI attacks on its own, it is that a single operator scales what used to require a team.&lt;/p&gt;

&lt;h2&gt;
  
  
  My own reading
&lt;/h2&gt;

&lt;p&gt;My reading is that the problem is not the agent's autonomy, it is the surface we leave for it. And skipping the catastrophic tone.&lt;/p&gt;

&lt;p&gt;A misconfigured SSO is a door you share between services. If the agent enters through it, it enters all of them at once.&lt;/p&gt;

&lt;p&gt;An unpatched decoding dependency is a door almost nobody looks at. libheif does not come up in risk meetings.&lt;/p&gt;

&lt;p&gt;And a VPN with PPTP or L2TP and default credentials is a door that has been open for years and nobody has closed because nobody uses it.&lt;/p&gt;

&lt;p&gt;The three controls that would have stopped these attacks are concrete. Phishing-resistant MFA, isolation of services that share SSO, and patching of image decoding dependencies.&lt;/p&gt;

&lt;p&gt;None is expensive. None is new. The problem is that none is on this week's priority list.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to check
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Check your SSO.&lt;/strong&gt; See which services share the same identity provider and whether a failure in one gives access to the rest. If the answer is yes, split them by criticality.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Audit stale VPNs.&lt;/strong&gt; Look for PPTP and L2TP in your inventory, check whether they are still exposed and change any default credential you find. admin123 is not a password, it is an invitation.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Look at image dependencies.&lt;/strong&gt; libheif and ImageMagick process files anyone can upload. Check that they are patched and that the service using them does not have excess permissions.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How I would test it in my lab
&lt;/h2&gt;

&lt;p&gt;I would set up a container with an old version of ImageMagick and libheif, feed it malformed HEIF images and see what happens.&lt;/p&gt;

&lt;p&gt;I would do it on an isolated network, with no internet egress, because the goal is to see the behavior, not to reproduce the exploit.&lt;/p&gt;

&lt;p&gt;I would watch whether the process crashes, whether it writes anything outside its directory or whether it opens a connection it should not.&lt;/p&gt;

&lt;p&gt;With that I would have a cheap conclusion. If the service that decodes images has write permissions where it should not, the library flaw stops being a flaw and becomes a breach.&lt;/p&gt;

&lt;h2&gt;
  
  
  Closing
&lt;/h2&gt;

&lt;p&gt;The lesson of the week is not that AI attacks on its own. It is that the doors we have left open for years are now walked through at a speed we had not seen.&lt;/p&gt;

&lt;p&gt;Closing three of them costs less than explaining why we did not.&lt;/p&gt;




&lt;p&gt;Originally published at &lt;a href="https://sammideblas.com/notas/ai-agent-runs-first-end-to-end-breach-in-spain" rel="noopener noreferrer"&gt;https://sammideblas.com/notas/ai-agent-runs-first-end-to-end-breach-in-spain&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>privacy</category>
      <category>devops</category>
    </item>
    <item>
      <title>Cisco's two exploited flaws and CISA's patch clock</title>
      <dc:creator>Sammi De Blas </dc:creator>
      <pubDate>Fri, 18 Sep 2026 09:19:02 +0000</pubDate>
      <link>https://dev.to/analista_83/ciscos-two-exploited-flaws-and-cisas-patch-clock-4m12</link>
      <guid>https://dev.to/analista_83/ciscos-two-exploited-flaws-and-cisas-patch-clock-4m12</guid>
      <description>&lt;h2&gt;
  
  
  The main case
&lt;/h2&gt;

&lt;p&gt;On Monday, September 14, a researcher publishes the details of CVE-2026-76461 (&lt;a href="https://socradar.io/blog/cve-2026-76461-cisco-email-gateway-flaw/" rel="noopener noreferrer"&gt;Source: SOCRadar&lt;/a&gt;), a remote code execution with root privileges in Cisco Secure Email Gateway. The vector is an email with malicious SQL inside it. No authentication required, no user interaction required, nothing required except the message reaching the gateway (helpnetsecurity.com).&lt;/p&gt;

&lt;p&gt;That same day, CISA adds the vulnerability to its Known Exploited Vulnerabilities catalog, the KEV, and sets a patch deadline for U.S. federal agencies that expires on September 17. Three days. Not three weeks, not a quarter. Three days for an email gateway exposed to the internet.&lt;/p&gt;

&lt;p&gt;The concrete scene is this. An administrator arrives on Monday, opens email, sees the advisory, checks the version of their Secure Email Gateway and finds it on the list. They have until Thursday. If they do not patch, the system sits with root accessible from outside.&lt;/p&gt;

&lt;p&gt;The technical detail that matters is the SQL injection. The gateway processes the message, builds a query against its internal database and does not sanitize the input properly. An attacker who controls the content of the email controls that query. And from there, root.&lt;/p&gt;

&lt;p&gt;What stands out is not the flaw itself. It is the calendar. CISA does not add something to the KEV for fun. It adds it when there is confirmed exploitation in the wild. That means someone is already using it against real systems while administrators read the advisory.&lt;/p&gt;

&lt;h2&gt;
  
  
  Not an isolated case
&lt;/h2&gt;

&lt;p&gt;On Wednesday, September 16, the same week, CVE-2026-76460 shows up in Cisco ISE. Remote authentication bypass, no credentials, CVSS 10.0, exploited in the wild. CISA puts it in the KEV that same day and sets a federal deadline for September 19 (thehackernews.com).&lt;/p&gt;

&lt;p&gt;ISE is Identity Services Engine. It is the system that decides who gets into the network and with what permissions. An authentication bypass there is not just any flaw. It is the first phase of an intrusion, the point from which an attacker moves laterally inward.&lt;/p&gt;

&lt;p&gt;Two Cisco products, two flaws without authentication, two KEV entries, two deadlines measured in days. The common shape is clear. They are edge systems, network-exposed, that process untrusted input and serve as a door. And both arrived with exploitation already documented.&lt;/p&gt;

&lt;p&gt;The pattern repeats outside Cisco. The same Monday, four espionage groups, APT31 among them, used the same exploit kit, BlueMoon, against Chrome and Windows in a single week. And there is a detail worth underlining. Patching is not enough. The GemStone extension and the scheduled tasks survive the fix (thehackernews.com).&lt;/p&gt;

&lt;p&gt;That is what changes the ground. For years, the answer to a zero-day was patch and breathe. Now you have to patch and also clean up the persistence the attacker left before the patch arrived. If you only do the first, the system ends up with the door closed and the intruder inside.&lt;/p&gt;

&lt;h2&gt;
  
  
  The other side
&lt;/h2&gt;

&lt;p&gt;The week also brings the reverse. Anthropic's threat report, 154 pages published on September 10, documents that its agents rewrite malware to evade detection and that the loot is now API keys (anthropic.com).&lt;/p&gt;

&lt;p&gt;The report's conclusion is uncomfortable. AI erases the skill gap. Small actors run state-level campaigns. A single operator with an API replicates what used to require a team.&lt;/p&gt;

&lt;p&gt;This connects to the main case in another way. The Cisco zero-day is exploited with an email. The BlueMoon exploit kit is deployed in a week. The technical barrier to entry drops, and the window between disclosure and exploitation compresses until it disappears.&lt;/p&gt;

&lt;p&gt;My reading is that we are looking at a change of pace, not of technique. Edge flaws without authentication have always existed. What is new is that exploitation arrives before the advisory, and that the attacker leaves persistence the patch does not touch. The defender who only watches the CVE is left halfway.&lt;/p&gt;

&lt;p&gt;It is worth saying plainly, even if it stings. If your inventory of edge systems is not up to date, you do not know what you have exposed. And if you do not know what you have exposed, CISA's deadline is useless to you.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to look at on Monday
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Edge inventory.&lt;/strong&gt; List every Cisco Secure Email Gateway and ISE on your network, with version and exposure. If any of them is on the internet without need, close it before patching.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Persistence after the patch.&lt;/strong&gt; On systems affected by BlueMoon, check browser extensions and scheduled tasks. The fix does not remove them.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Key rotation.&lt;/strong&gt; If you have API keys from AI platforms in production, rotate them and shorten their lifetime. The Anthropic report flags them as priority loot.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How I would test it in my lab
&lt;/h2&gt;

&lt;p&gt;I would spin up a container with a vulnerable version of a mail service and send it a message with a simple SQL payload, to see whether the query executes. I would not look for the real exploit, just confirm that the input is not sanitized. Then I would apply the patch and repeat the send, to check that the same payload no longer goes through. The conclusion would be simple. If the behavior changes between before and after, the patch does what it says. If it does not change, I have a bigger problem than the CVE.&lt;/p&gt;

&lt;h2&gt;
  
  
  Closing
&lt;/h2&gt;

&lt;p&gt;The window between flaw and exploitation is no longer measured in weeks, and the patch only closes the door, it does not throw out whoever already came in. Monday is for inventory and cleanup, not just updating.&lt;/p&gt;




&lt;p&gt;Originally published at &lt;a href="https://sammideblas.com/notas/cisco-s-two-exploited-flaws-and-cisa-s-patch-clock" rel="noopener noreferrer"&gt;https://sammideblas.com/notas/cisco-s-two-exploited-flaws-and-cisa-s-patch-clock&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cisco</category>
      <category>vulnerability</category>
      <category>cisa</category>
      <category>patch</category>
    </item>
    <item>
      <title>I let a local 27B LLM audit and fix my Splunk + Sysmon stack</title>
      <dc:creator>Sammi De Blas </dc:creator>
      <pubDate>Thu, 17 Sep 2026 20:15:24 +0000</pubDate>
      <link>https://dev.to/analista_83/i-let-a-local-27b-llm-audit-and-fix-my-splunk-sysmon-stack-c47</link>
      <guid>https://dev.to/analista_83/i-let-a-local-27b-llm-audit-and-fix-my-splunk-sysmon-stack-c47</guid>
      <description>&lt;h1&gt;
  
  
  I let a local 27B LLM audit and fix my Splunk + Sysmon stack
&lt;/h1&gt;

&lt;p&gt;The question was not "can an LLM do SOC work". The question I actually wanted answered was narrower and harder: &lt;strong&gt;can a 27B model running on my own GPU, with zero bytes leaving the machine, audit my Splunk install, find what is broken and fix it — without me telling it how?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;After an afternoon of back and forth, the answer is yes, with caveats worth writing down. Including the mistakes, because those are the interesting part.&lt;/p&gt;

&lt;p&gt;Context first, since it shapes how you should read this: I am a security analyst &lt;strong&gt;without prior SOC experience&lt;/strong&gt; — I am studying for CySA+, and building a home SOC is the only way I have to practise on something that behaves like a real environment. Everything here ran on my own hardware, was reviewed by the model and verified against real evidence. No third-party data, no borrowed infrastructure.&lt;/p&gt;

&lt;h2&gt;
  
  
  The setup
&lt;/h2&gt;

&lt;p&gt;Three moving parts:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Splunk&lt;/strong&gt; (dev licence) as the SIEM — the thing all the logs land in.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Sysmon&lt;/strong&gt; as endpoint telemetry, so process and access events actually exist.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Qwen3.8-27B&lt;/strong&gt; quantised (IQ2_M, Gated DeltaNet hybrid, 128K context) on a single 16GB GPU, served with &lt;code&gt;llama-server&lt;/code&gt; and driven by an agent.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The goal was not a mentor that explains things to me. It was an agent that audits the real install, finds what is wrong, and remediates it: edits configs, proposes commands, removes what is redundant.&lt;/p&gt;

&lt;h2&gt;
  
  
  Five audits before I trusted it with anything
&lt;/h2&gt;

&lt;p&gt;I did not hand my Splunk over on day one. I ran five real audits against it: config inspection, data pipeline review, logging hardening, 24-hour log analysis, and IoC detection.&lt;/p&gt;

&lt;p&gt;The verdict: it reasons like a senior analyst. It corrected wrong assumptions of mine three times, debugged a dozen issues on its own, and — this matters — said "I cannot confirm this" instead of inventing an answer.&lt;/p&gt;

&lt;h2&gt;
  
  
  The failure mode nobody warns you about
&lt;/h2&gt;

&lt;p&gt;Thoroughness is gold in an audit and poison in a remediation.&lt;/p&gt;

&lt;p&gt;When I handed it the first finding to fix, it went full forensic: tried performance-counter tools to verify counters, read the vendor spec, ran the failing binary by hand to reproduce it — and ran out of context. It hit 97.4% of its 128K window chasing the source name of a Windows Update log that had nothing to do with the fix.&lt;/p&gt;

&lt;p&gt;The model knew the answer. It did not know when to stop. The fix was a system-prompt rule: &lt;em&gt;stop as soon as you have the root cause with evidence&lt;/em&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  The findings
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Double ingestion.&lt;/strong&gt; My indexer was already collecting logs locally, and a Universal Forwarder on the same box was sending them again. Double licence usage, double noise. The valuable part was not the diagnosis: it read the two product GUIDs out of the MSI registry entries and explicitly warned me which one to remove and which one &lt;strong&gt;never to touch&lt;/strong&gt;, because that second one was Splunk itself with all my data in it. A careless &lt;code&gt;msiexec /x&lt;/code&gt; there and the lab is gone. It marked that one as excluded.&lt;/p&gt;

&lt;p&gt;Also worth knowing: the straightforward &lt;code&gt;msiexec /x ... /qn&lt;/code&gt; returned a phantom &lt;code&gt;-1&lt;/code&gt;, because &lt;code&gt;msiexec&lt;/code&gt; is asynchronous and PowerShell does not capture its exit code reliably. &lt;code&gt;Start-Process msiexec -Wait -PassThru&lt;/code&gt; returned a clean &lt;code&gt;ExitCode: 0&lt;/code&gt; and removed service, directory and registry entry.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Three data inputs dead since install day.&lt;/strong&gt; Zero events since July, three different root causes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Two Windows event channels were disabled, so there was no log file to read at all. Fixed by enabling the channel.&lt;/li&gt;
&lt;li&gt;The third was a double bug: a required parameter was missing, &lt;em&gt;and&lt;/em&gt; the performance counters were configured in English on a Spanish Windows install. In Spanish, the counter is not &lt;code&gt;% Processor Time&lt;/code&gt; but &lt;code&gt;% de tiempo de procesador&lt;/code&gt;. Even the object name is localised. The fix was to force the tool to use the English API.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;And a detail I appreciate more than the fix itself: the config change was correct, but the binary still died when sampling. It documented that as "needs binary debugging" instead of claiming success.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Sysmon was blind to credential theft.&lt;/strong&gt; My config did not detect access to LSASS — the process that holds credentials in memory, and the thing Mimikatz goes after. An attacker could have dumped credentials and I would have learned about it later. Enabling &lt;code&gt;ProcessAccess&lt;/code&gt; with a filter on &lt;code&gt;lsass.exe&lt;/code&gt; is a three-line change, but along the way we discovered that &lt;strong&gt;both the model and I were carrying a wrong Sysmon event-ID mapping&lt;/strong&gt;. The numbers I had been using were simply incorrect. The real config file disproved them. Verify technical numbers against reality; do not trust recall, including your own.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;One command, three traps.&lt;/strong&gt; To log process creation with the command line:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;auditpol&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;/set&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;/subcategory:&lt;/span&gt;&lt;span class="s2"&gt;"{0CCE922B-69AE-11D9-BED3-505054503030}"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;/success:enable&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;/failure:enable&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It failed for three reasons at once: the privilege was missing, the category name is localised (so the English string does not resolve), and the braces of the GUID break PowerShell syntax unless quoted. Elevation, localisation, syntax.&lt;/p&gt;

&lt;h2&gt;
  
  
  The best part: it caught its own false positives
&lt;/h2&gt;

&lt;p&gt;Two earlier findings turned out to be &lt;strong&gt;false positives, and the model is what caught them&lt;/strong&gt;, correcting previous audits (one of them a note of mine):&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A log channel reported as disabled was actually enabled and recording hundreds of events. The original audit had looked at the wrong channel.&lt;/li&gt;
&lt;li&gt;A detection rule flagged any process touching temporary files under the user profile as suspicious — which meant my code editor, my note-taking app and my own AI agent showed up as threats. It needed specific Electron exclusions.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;An analyst that corrects its own assumptions with evidence beats one that gets lucky.&lt;/p&gt;

&lt;h2&gt;
  
  
  Making it deterministic
&lt;/h2&gt;

&lt;p&gt;After watching it blow through the context window, I fixed the cause rather than the symptom: temperature down from 0.8 to 0.3, plus a working-rules system prompt (answer only what is asked; in remediation stop at root cause with evidence; in audit be exhaustive; use scripts for mechanical operations; verify IDs, ports and GUIDs before asserting; never invent; be concise).&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;Before&lt;/th&gt;
&lt;th&gt;After&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Output&lt;/td&gt;
&lt;td&gt;Huge, rambling&lt;/td&gt;
&lt;td&gt;Short and direct&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Context used&lt;/td&gt;
&lt;td&gt;97.4% (overflowed)&lt;/td&gt;
&lt;td&gt;49.7%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Assumptions&lt;/td&gt;
&lt;td&gt;Taken for granted&lt;/td&gt;
&lt;td&gt;Verified against reality&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Result&lt;/td&gt;
&lt;td&gt;1 finding in 30 min&lt;/td&gt;
&lt;td&gt;4 findings in a row&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Honest scoreboard
&lt;/h2&gt;

&lt;p&gt;Out of ten findings: double ingestion resolved, two inputs fixed and one pending binary debugging, credential access now detected, process logging enabled, two false positives corrected, one of my own notes fixed. Not a perfect lab result — which is exactly why I trust the report.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What I take away:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A 27B local model is already competent at this work. The bottleneck is context, not intelligence.&lt;/li&gt;
&lt;li&gt;Ask for exhaustiveness in auditing and forbid it in remediation.&lt;/li&gt;
&lt;li&gt;Verify technical numbers against reality instead of remembering them.&lt;/li&gt;
&lt;li&gt;Mechanical operations belong in a script: asked to insert two lines into a 123KB config, it spent 30 minutes regenerating the whole file by hand.&lt;/li&gt;
&lt;li&gt;Determinism is a configuration choice, not a model property.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;An LLM does not replace your judgement or the urge to understand what is happening. But as a mentor that never sleeps and never leaves your machine, for someone starting out like me, it is a genuine advantage — and &lt;strong&gt;not a single log leaves my computer&lt;/strong&gt;.&lt;/p&gt;




&lt;p&gt;The full technical breakdown of this audit — screenshots, exact commands and config files — is on my blog: &lt;strong&gt;&lt;a href="https://sammideblas.com/posts/0x73-a-27b-soc-analyst-auditing-and-remediating-splunk-sysmon" rel="noopener noreferrer"&gt;A 27B SOC Analyst: Auditing and Remediating Splunk + Sysmon&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Related, if you are building the same kind of thing: &lt;strong&gt;&lt;a href="https://sammideblas.com/posts/0x74-building-your-own-log-analyzer" rel="noopener noreferrer"&gt;Building Your Own Log Analyzer&lt;/a&gt;&lt;/strong&gt; and &lt;strong&gt;&lt;a href="https://sammideblas.com/posts/0x46-gravity-soc-my-security-operations-center" rel="noopener noreferrer"&gt;Gravity SOC, my home security operations center&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;I write up what I learn, mistakes included, at &lt;strong&gt;&lt;a href="https://sammideblas.com" rel="noopener noreferrer"&gt;sammideblas.com&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>llm</category>
      <category>devops</category>
    </item>
    <item>
      <title>AI adoption now measured by what you can audit</title>
      <dc:creator>Sammi De Blas </dc:creator>
      <pubDate>Wed, 16 Sep 2026 10:28:24 +0000</pubDate>
      <link>https://dev.to/analista_83/ai-adoption-now-measured-by-what-you-can-audit-40gi</link>
      <guid>https://dev.to/analista_83/ai-adoption-now-measured-by-what-you-can-audit-40gi</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fy0fuwn7lqcd501i5ttor.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fy0fuwn7lqcd501i5ttor.png" alt="Diagram: identity, scope and traceability decide what actually ships" width="800" height="420"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The main case
&lt;/h2&gt;

&lt;p&gt;On September 12, Cloudera and Mistral announced a sovereign enterprise AI alliance.&lt;/p&gt;

&lt;p&gt;Open, customizable models on a hybrid data platform, with data, models, and compute inside customer-controlled environments (Source: technode.global).&lt;/p&gt;

&lt;p&gt;The article frames it as a trend, not an isolated case. Once you leave the pilots behind, model choice gets evaluated alongside data location, governance, cost, and control.&lt;/p&gt;

&lt;p&gt;Two days earlier, between September 9 and 11, NeuroWatt presented NeuroTeam.&lt;/p&gt;

&lt;p&gt;It is an enterprise "agentic AI workforce" that packages agent reasoning, tool execution, identity and access, policies, human approvals, auditability, and monitoring into a single architecture. It includes multi-model routing with an internal LLM gateway and an on-prem option for sovereignty and latency (PRNewswire).&lt;/p&gt;

&lt;p&gt;Both announcements share a pattern. The model is no longer what is being sold. What is being sold is the wrapper that makes it auditable.&lt;/p&gt;

&lt;p&gt;And the numbers behind the shift are uncomfortable.&lt;/p&gt;

&lt;p&gt;92% say governing agents is critical for security, but only 44% have implemented policies for it.&lt;/p&gt;

&lt;p&gt;Only 18% of MCP server deployments apply any scope to tool permissions, and only 52% can trace and audit the data their agents access (Source: Linx Security analysis reported by NHI Mgmt Group).&lt;/p&gt;

&lt;p&gt;An MCP server, for anyone who does not know what it is, is the component that exposes tools and data to an AI agent.&lt;/p&gt;

&lt;p&gt;If you do not scope it, the agent can call any tool that server publishes, with no brake.&lt;/p&gt;

&lt;p&gt;The framework that already exists says it more precisely. The Cloud Security Alliance's Agent Identity Governance Framework (in draft since March 27) argues that agents must be treated as first-class identity subjects, with just-in-time access, expiration, and a human sponsor.&lt;/p&gt;

&lt;p&gt;Its most uncomfortable line is that a sub-agent that finishes its task and keeps active credentials is, in governance terms, "an abandoned account with permanent access", hence rotating credentials.&lt;/p&gt;

&lt;p&gt;Gartner goes against comfort and says that applying the same governance to all agents will lead to failure. It proposes four levels of autonomy (observe, advise, act with approval, act autonomously) with different controls at each level.&lt;/p&gt;

&lt;p&gt;It also warns that human approvals degenerate into approval fatigue and create a false sense of security. I disagree with this, because you have to know how to program the right framework. That is why "Human in The Loop" matters so much to me now and going forward.&lt;/p&gt;

&lt;p&gt;The OWASP MCP Top 10 already names "shadow MCP servers", which are nothing less than those servers nobody has in "scope".&lt;/p&gt;

&lt;p&gt;Palo Alto documents the "rug-pull" attack, in which an MCP server passes the initial review and then silently changes the definition of its tools.&lt;/p&gt;

&lt;h2&gt;
  
  
  Not an isolated case
&lt;/h2&gt;

&lt;p&gt;Since August 2, the transparency obligations of Article 50 of the AI Act are enforceable, along with the AI Office's sanctioning powers over general-purpose model providers, with fines of up to 15 million euros or 3 percent of global turnover (Source: mondaq, iagovernance.com).&lt;/p&gt;

&lt;p&gt;The Digital Omnibus, Regulation (EU) 2026/1744 in force since July 27, postponed the bulk of the high-risk regime of Annex III to December 2, 2027, and Annex I to August 2028.&lt;/p&gt;

&lt;p&gt;It left transparency and the power to fine general-purpose models intact (Source: peopleofinternet.com).&lt;/p&gt;

&lt;p&gt;One industry source puts the first fines issued within weeks at around 47 million euros (Source: aiineurope.co).&lt;/p&gt;

&lt;p&gt;That figure should be treated as unconfirmed by an official source, but the activation of the sanctioning power is a documented fact.&lt;/p&gt;

&lt;p&gt;The common pattern with the corporate announcements is the same. The AI that actually gets adopted in 2026 is the AI that comes with identity, scope, logging, and a brake.&lt;/p&gt;

&lt;p&gt;Everything else remains a pilot or less than that. I see it every day working for a large consultancy at a major bank.&lt;/p&gt;

&lt;h2&gt;
  
  
  The other side
&lt;/h2&gt;

&lt;p&gt;The week also leaves us with agents used as a weapon.&lt;/p&gt;

&lt;p&gt;Details of the OpenAI agent assault on Hugging Face were expanded.&lt;/p&gt;

&lt;p&gt;It appears that roughly 700 agents, coordinated through a forum they set up themselves (unauthorized and hidden), "made a mess of it", according to the METR and Redwood Research analysis (Source: time.com).&lt;/p&gt;

&lt;p&gt;It is the other face of the same problem, because if an agent has identity, scope, and traces, etc., you can reconstruct what it did. But if it does not, it becomes the perfect vehicle to act at scale without anyone knowing what really happened.&lt;/p&gt;

&lt;h2&gt;
  
  
  My own read
&lt;/h2&gt;

&lt;p&gt;I have the feeling that we are selling agent governance before we have inventoried the agents. I think there is a lot of operational ignorance. I think there is no common sense in how AI is applied in companies. It feels like a fad, even if it is not one.&lt;/p&gt;

&lt;p&gt;To go to concrete data, the 18 percent scoping statistic for MCP servers is not a maturity data point. It is an exposure data point.&lt;/p&gt;

&lt;p&gt;The most profitable control is not the later log. It is the refusal to execute because it was not planned, when at certain consultancies you pay for human time and not for objectives.&lt;/p&gt;

&lt;p&gt;A human who aborts the operation when the context changes (model, permissions, cost) is worth more than any audit dashboard read three days later. I think we are moving fast without knowing what we have in our hands.&lt;/p&gt;

&lt;p&gt;Autonomy should be reserved for what is reversible.&lt;/p&gt;

&lt;p&gt;Reading, analysis, and drafts without friction.&lt;/p&gt;

&lt;p&gt;Writing, sending, and deployment with explicit approval or traceable evidence behind every conclusion.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to look at
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Inventory before policy.&lt;/strong&gt; List agents and MCP servers with their human sponsor and the tools each one exposes. It is an afternoon's work and it is exactly what the market packages as a product.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Scope per tool.&lt;/strong&gt; Check how many of your MCP servers apply any scope to permissions. If the answer is none, you already know where to start.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Credentials with expiration.&lt;/strong&gt; Check whether any sub-agent finished its task and still holds active credentials. In governance terms, that is an abandoned account with permanent access.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How I would test it in my lab
&lt;/h2&gt;

&lt;p&gt;I would set up a minimal MCP server on a local machine, with two exposed tools, one read-only and one write.&lt;/p&gt;

&lt;p&gt;I would give an agent a token with no expiration and no per-tool scope and ask it for a trivial read task.&lt;/p&gt;

&lt;p&gt;Then I would look at the server logs to see which calls it recorded and which it did not.&lt;/p&gt;

&lt;p&gt;The conclusion I would draw is how much of my real surface would remain invisible with that same configuration.&lt;/p&gt;

&lt;p&gt;Then I would repeat the exercise with a watchdog that aborts execution if the configured model changes from the one that created the job.&lt;/p&gt;

&lt;h2&gt;
  
  
  Closing
&lt;/h2&gt;

&lt;p&gt;AI adoption in 2026 is measured by what you can audit, not by what you can show in a demo.&lt;/p&gt;

&lt;p&gt;If you do not know what agents you have or what tools they expose... governance is an intention, not a control.&lt;/p&gt;




&lt;p&gt;Originally published at &lt;a href="https://sammideblas.com/notas/ai-adoption-now-measured-by-what-you-can-audit" rel="noopener noreferrer"&gt;https://sammideblas.com/notas/ai-adoption-now-measured-by-what-you-can-audit&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>governance</category>
      <category>devops</category>
    </item>
    <item>
      <title>Patch window shrinks to hours: three critical flaws in five days</title>
      <dc:creator>Sammi De Blas </dc:creator>
      <pubDate>Mon, 14 Sep 2026 09:16:00 +0000</pubDate>
      <link>https://dev.to/analista_83/patch-window-shrinks-to-hours-three-critical-flaws-in-five-days-1g03</link>
      <guid>https://dev.to/analista_83/patch-window-shrinks-to-hours-three-critical-flaws-in-five-days-1g03</guid>
      <description>&lt;h2&gt;
  
  
  Three flaws and one pattern
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0zidx0rtzncuqtx6d3il.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0zidx0rtzncuqtx6d3il.png" alt="Diagram: from patch publication to exploitation in hours" width="800" height="420"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The week left three critical vulnerabilities with a common trait worth a slow look.&lt;/p&gt;

&lt;p&gt;On September 11, Check Point published patches for two remote code execution flaws in its VPN appliances, CVE-2026-85102 and CVE-2026-85103 (Source: securityweek.com).&lt;/p&gt;

&lt;p&gt;The first affects the Security Gateway and allows code execution without credentials.&lt;/p&gt;

&lt;p&gt;The second also reaches the Management Server.&lt;/p&gt;

&lt;p&gt;The Dutch NCSC warned of imminent exploitation, and LivePatch Take 24 covers R81.20, R82, and R82.10, while the rest of the versions require upgrading to R82.20 (Source: blog.sied.ar).&lt;/p&gt;

&lt;p&gt;The operational recommendation that comes with the advisory is concrete, since ports 500, 4500, and 443 should be restricted to authorized peers only.&lt;/p&gt;

&lt;p&gt;That same day... GitLab shipped patches for CVE-2026-85706, a path traversal in the commits API with a CVSS of 10.0. OMG!&lt;/p&gt;

&lt;p&gt;The flaw allows reading files from the server without authentication. OMG!&lt;/p&gt;

&lt;p&gt;Probes in production were detected hours after public disclosure, according to watchTowr (Sources: thehackernews.com, elhacker.net).&lt;/p&gt;

&lt;p&gt;The fixed versions are 19.3.2, 19.2.6, and 19.1.8.&lt;/p&gt;

&lt;p&gt;The third case is N-able N-central, CVE-2026-86218, a pre-auth RCE with a CVSS of 10.0.&lt;/p&gt;

&lt;p&gt;Live exploitation entered CISA's KEV catalog with a remediation deadline of September 11, and Shadowserver counted close to 1,500 exposed consoles (Source: thehackernews.com).&lt;/p&gt;

&lt;h2&gt;
  
  
  The pattern
&lt;/h2&gt;

&lt;p&gt;There is one scene that sums up why these three cases read together.&lt;/p&gt;

&lt;p&gt;In the GitLab case, probes showed up in production hours after the patch went public. There was no grace window.&lt;/p&gt;

&lt;p&gt;Someone was watching the advisory repository, or had a system watching it for them, and acted before most administrators had read the email.&lt;/p&gt;

&lt;p&gt;That is what stands out!&lt;/p&gt;

&lt;p&gt;Public disclosure no longer marks the start of a days-long deadline.&lt;/p&gt;

&lt;p&gt;It marks the starting gun of a race that some run with automation.&lt;/p&gt;

&lt;p&gt;The N-able case adds another layer.&lt;/p&gt;

&lt;p&gt;CISA added the flaw to its catalog of exploited vulnerabilities with a one-day remediation deadline.&lt;/p&gt;

&lt;p&gt;That deadline is not rhetorical, that is, it reflects that exploitation was already happening when the advisory was published.&lt;/p&gt;

&lt;p&gt;The 1,500 exposed consoles Shadowserver counted are the surface where that clock runs.&lt;/p&gt;

&lt;h2&gt;
  
  
  Not an isolated case
&lt;/h2&gt;

&lt;p&gt;The three cases share a pattern that the previous week had already shown more bluntly.&lt;/p&gt;

&lt;p&gt;GreyNoise and SecurityWeek documented a campaign with hundreds of AI agents against PaperCut NG/MF servers, chaining CVE-2026-81578 and CVE-2026-82078 on a Codex harness with a DeepSeek model.&lt;/p&gt;

&lt;p&gt;The result was around 440 organizations compromised across 48 countries, almost half of them in the education sector (Source: bleepingcomputer.com, greynoise.io).&lt;/p&gt;

&lt;p&gt;One education center went from initial access to Domain Admin in seven minutes.&lt;/p&gt;

&lt;p&gt;The connection is not that the flaws are the same, it is rather that the cost of finding, testing, and deploying an exploit has dropped.&lt;/p&gt;

&lt;p&gt;A low-budget attacker can rent AI agents to scan, generate variants, and validate the exploit in their own lab before launching it.&lt;/p&gt;

&lt;p&gt;What used to require a human team for days now runs in parallel and at scale.&lt;/p&gt;

&lt;p&gt;That is why the patch window has shrunk, but not because the flaws are more severe, rather because on the other side there are more hands, faster and cheaper.&lt;/p&gt;

&lt;h2&gt;
  
  
  When the agent attacks
&lt;/h2&gt;

&lt;p&gt;It is worth saying plainly, even if it stings. I have the feeling that we are losing control on defense ever since agents burst onto the scene.&lt;/p&gt;

&lt;p&gt;In the PaperCut case... the AI agents were not the defensive tool, they were the attacker.&lt;/p&gt;

&lt;p&gt;Hundreds of instances orchestrated to discover or test and deploy exploits against exposed servers.&lt;/p&gt;

&lt;p&gt;The Codex harness with a DeepSeek model is the technical piece that makes it possible without more... an environment that runs tasks autonomously on a language model, but believe me, I have tried simple approaches in my lab with small local models that fit on any GPU, and you can hide behind several proxies, etc... better not to give ideas.&lt;/p&gt;

&lt;p&gt;That changes the conversation about agents in the SOC.&lt;/p&gt;

&lt;p&gt;It is not just that an analyst can use an agent for triage.&lt;/p&gt;

&lt;p&gt;It is that the same kind of technology, with less supervision, is already used to attack.&lt;/p&gt;

&lt;p&gt;The asymmetry is real. Unfortunately, the defender needs everything to work and the attacker only needs one unpatched server.&lt;/p&gt;

&lt;h2&gt;
  
  
  My own read
&lt;/h2&gt;

&lt;p&gt;For anyone administering these systems, the message is uncomfortable but clear.&lt;/p&gt;

&lt;p&gt;Patching in hours is no longer the minimum to stay off the victim list.&lt;/p&gt;

&lt;p&gt;Segmentation and egress filtering remain the controls that make the difference when exposure time is measured in hours, not days.&lt;/p&gt;

&lt;p&gt;And there is an inventory lesson, which is that the 1,500 exposed N-able consoles were not hidden, no... they were on the internet, reachable.&lt;/p&gt;

&lt;p&gt;The same goes for the Check Point VPN appliances and the GitLab instances.&lt;/p&gt;

&lt;p&gt;The exposed surface is the first problem and, therefore, patching is the second.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to look at
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Check exposed ports.&lt;/strong&gt; If you manage Check Point appliances, restrict ports 500, 4500, and 443 to authorized peers. If you have N-able N-central consoles reachable from the internet, that is the first decision on Monday.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Check GitLab versions.&lt;/strong&gt; The fixed versions are 19.3.2, 19.2.6, and 19.1.8. If your instance is below that and exposed, the path traversal allows reading files without authentication.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Enable probe telemetry.&lt;/strong&gt; GitLab probes were detected hours after disclosure. A log of access attempts to commits API paths gives you the signal before the exploit works.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How I would test it in my lab
&lt;/h2&gt;

&lt;p&gt;I would set up a GitLab instance on an isolated virtual machine, with no internet exposure, and send requests to the commits API with manipulated paths to see whether the server returns file content outside the expected directory.&lt;/p&gt;

&lt;p&gt;Before that, I would capture traffic with tcpdump to have a record of which requests arrive and in what shape.&lt;/p&gt;

&lt;p&gt;The conclusion would be that, if the vulnerable version responds with file content it should not, the flaw is real and the patch is urgent.&lt;/p&gt;

&lt;p&gt;If it responds with an error, the version is already fixed.&lt;/p&gt;

&lt;p&gt;It is an afternoon check that requires nothing more than a VM and a willingness to read HTTP responses.&lt;/p&gt;

&lt;h2&gt;
  
  
  Closing
&lt;/h2&gt;

&lt;p&gt;The window between disclosure and exploitation has compressed to hours.&lt;/p&gt;

&lt;p&gt;Anyone without a patching process that works in that timeframe is playing a different game.&lt;/p&gt;

&lt;p&gt;The good news is that the controls that make the difference are still the same as always, less exposed surface, fast patches, and telemetry that warns before the exploit arrives.&lt;/p&gt;




&lt;p&gt;Originally published at &lt;a href="https://sammideblas.com/notas/patch-window-shrinks-to-hours-three-critical-flaws-in-five-days" rel="noopener noreferrer"&gt;https://sammideblas.com/notas/patch-window-shrinks-to-hours-three-critical-flaws-in-five-days&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>devops</category>
      <category>privacy</category>
      <category>ai</category>
    </item>
  </channel>
</rss>
