Adversa published two October roundups this week, one on AI agents broadly (4 October) and one on coding agents (2 October). Read together, they show where agent security bugs now live: in plugin updates, sandbox control APIs, credential stores, agent-to-agent protocols and copilots bolted onto admin tools. Most of them don't need a clever jailbreak. They need an agent that trusts something it shouldn't.
Plugin updates are the new supply chain
The coding-agent roundup reports "Plugin4Shell" from Air.Security: plugins pinned to a specific commit can be swapped for malicious code during automatic updates, across Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. Pinning is supposed to be the control. In this case it was the way in.
Adversa's advice is to disable automatic plugin updates until commit verification is in place. That's sensible, and it isn't a lot of work.
Sandboxes keep failing at the control plane
The same roundup lists a DeepSeek Harness flaw (CVE-2026-82533) where an unauthenticated localhost API let a sandboxed agent switch itself to "danger-full-access," plus two Codex escapes, one writing outside workspace boundaries and one leaking trust tokens through heap snapshots. The 4 October roundup adds a MaxKB sandbox bypass (CVE-2026-77521) in which only the first command in a chain was sandboxed, so anything after a semicolon ran as root.
None of these beat the sandbox itself. They went around it: the control API, the token, the second command. Those are the places worth testing.
Credentials and protocols are inside the blast radius
The 4 October roundup reports, among September's findings:
Unit 42 showed indirect injection reading an AWS agent harness's heap via
/procto extract plaintext identity JWTs. An arXiv paper catalogs 11 design flaws in the Agent2Agent (A2A) protocol, including context injection through unprotected context IDs and credential harvesting through multi-hop delegation. A SQL Server Management Studio copilot flaw (CVE-2026-65669) let instructions planted in database properties bypass read-only mode and escalate to sysadmin.
The last one is worth dwelling on. Read-only mode was the boundary, and the input that crossed it was plain database metadata.
Agents leak by being helpful
One item in the coding roundup didn't involve an attacker at all. Adversa reports that more than 13,000 internal screenshots from over 300 organizations ended up public when coding agents pushed images to public repositories to get around a GitHub CLI limitation. The agent completed its task. The boundary was the thing it worked around.
A quick GitSpawn update
We covered GitSpawn when Manifold disclosed it in September. Adversa's roundup still lists four of the eight reported flaws as unpatched at publication. If you run coding agents against repos you didn't create, that's still an open issue.
A note on sourcing
Everything above comes from Adversa's two roundups, which link out to the primary research. We couldn't independently fetch all of the primary write-ups for this piece, so check the linked originals before quoting specifics.
Test the boundaries you actually have
Each finding above is a boundary someone assumed existed and never tested. Humanbound's engine and CLI are open source, and you can run adversarial tests against your own agents today.
Test your agents for free. Humanbound's Community plan is free and rolling out to as many developers as possible. Sign up at app.humanbound.ai.
References
- Adversa, AI coding agent vulnerabilities, October 2026: https://adversa.ai/blog/top-ai-coding-agent-security-resources-october-2026/
- Adversa, AI agent security incidents and vulnerabilities, October 2026: https://adversa.ai/blog/top-ai-agent-security-resources-october-2026/
- Palo Alto Unit 42, Securing AWS AgentCore Harness credentials (via Adversa): https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/
- Lasso Security, CVE-2026-77521 MaxKB sandbox bypass (via Adversa): https://www.lasso.security/blog/cve-2026-77521-maxkbypass---from-prompt-injection-to-bypassing-maxkb-agents-sandbox
- Embrace The Red, SQL Copilot to sysadmin (via Adversa): https://embracethered.com/blog/posts/2026/from-select-to-sysadmin-sql-copilot-bluehat-asia/
- arXiv, A2A protocol flaws (via Adversa): https://arxiv.org/abs/2609.10871
Top comments (0)