Welcome to issue #117 of the Resilient Cyber Newsletter!
Last week was about what the OpenAI agents did.
This week the conversation moved on to who answers for it and which controls are worth trusting. The UK AISI published a post-mortem of its own agent incident, a third forensics team pieced together more of the OpenAI activity from public artifacts, John Kindervag argued zero trust still works, two senators introduced a liability bill, and a VC published a long essay arguing the kill switch everyone keeps legislating for is really twelve switches owned by twelve different people.
Sam Altman also told Politico the world should accept “some bad things happening,” which certainly set the mood.
The second thread is access and remediation.
Anthropic turned Glasswing into a tiered verification program, Joshua Saxe argued trusted-access programs are far too small, Paul Nakasone asked the labs to lend their models to critical infrastructure, AWS put an 89% number on autonomous find-validate-fix, and Reflection is shipping a 500B parameter open-weight model with a pitch that openness is the safer path.
Let’s get into it!
Cyber Leadership & Market Dynamics
Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation

Kevin Mandia’s Armadin raised a $255.5 million Series B at a valuation north of $2.5 billion, co-led by a16z and Accel, taking total funding to roughly $445 million just seven months after launch. Armadin runs swarms of offensive agents that chain minor findings into validated attack paths, and its August exercise with TENEX.ai put 26,000 agents through roughly 17 million offensive actions against 25,000+ services, producing 238 findings and 38 validated attack paths without privileged credentials.
Kevin also went on The a16z Show and said Armadin has found over 90 zero-days in production environments this year. Continuous AI-driven offensive validation is quickly becoming table stakes, and the annual pentest PDF is starting to look like a fax machine.
I caught Kevin’s interview on the show and found it to be a great conversation for the state of AI’s impact on Cyber, particularly for OffSec.
Accenture contractor removed from FBI following damaging data breach
A follow-up to the FBI breach I covered last week.
Reuters reports the Bureau removed the Accenture contractor responsible for the PeopleSoft HR platform ShinyHunters came through, and FBI cyber chief Brett Leatherman put the cause on the record, saying the contractor “failed to implement a security patch explicitly issued to secure the platform.” Accenture declined to answer specifics, and a second alleged ShinyHunters leader was arrested in Jordan on October 3.
Accenture deserves the scrutiny, that said, the patch existed and the warnings were public, and the rest of this issue is about agents finding novel bugs in days while a three-letter agency got popped by a known one.
I’ve worked in large Federal agencies, and it isn’t surprising that they were behind on patches, but it is amazing that a single missed patch led to this, which speaks to the nature of the architecture more broadly than any single patch.
How the government can partner with the private sector on AI cybersecurity
Paul Nakasone, former head of NSA and Cyber Command and now on OpenAI’s board, argues there is a narrow window to put frontier models to work hardening critical infrastructure before adversaries have comparable access. His framing aligned with OpenAI’s “Defenders Window”, which isn’t surprising given his board role.
He wants every leading US lab to volunteer models for real infrastructure missions, deeper partnerships across government, private network owners and academia, and hands-on integration help for hospitals and water utilities, pointing to a Texas and federal pilot on water systems called Project Watershed 250.
Keep the board seat in mind while reading, since the company whose agents kicked off this whole news cycle is the one he helps govern. Still, his proposed metric is a good one. Success should be “measured not by how many vulnerabilities an AI system discovers, but by how many are verified, prioritized and fixed,” which is exactly the gap the AWS item below is trying to close.
Sens. Hawley, Murphy push AI liability as Trump backs self-regulation
Sens. Josh Hawley and Chris Murphy introduced the AI Agent Accountability Act, which would make companies criminally and civilly liable for hacking incidents involving their AI agents, arguing current law is ambiguous about who answers when an agent attacks something.
The administration’s position, via DNI Jay Clayton, is that product liability law and the DOJ already cover it. Axios also rounds up the pending kill-switch bills and notes Speaker Johnson called earlier bipartisan work “rendered obsolete” by the pace of change.
A liability bill was always coming after the last month, and the ambiguity the senators describe is real. Whether criminal liability for emergent agent behavior is workable is another question, and the kill-switch bills run headlong into Kevin Skapinetz’s essay further down.
Nothing passes before the election, but the framing for next year is now set.
Speaking of discussions on these topics, the Senate Homeland Security Committee held a hearing on “Rogue AI”, which was excellent, and I highly recommend folks give it a watch.
Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks

John Kindervag, who coined zero trust in Forrester’s 2010 “No More Chewy Centers” report, has a new book out on zero trust for the AI era, and his case is that AI-generated traffic still has to cross the same network attackers always have, so “correctly implemented zero trust can still halt it.” His condition is that the policy engine accurately reflects your real posture and is protected from rogue agents and insiders tampering with it.
I agree with John, with the caveat that “correctly implemented” is carrying a lot of weight. The rogue agent incidents this year involved harvested cloud credentials and lateral movement inside clusters, which is the chewy center he was warning about sixteen years ago, and in my experience most zero trust programs are still a work in progress and always will be by a large margin.
AI
AI Is Exposing Decades of Security Debt
I had a chance to join the team over at Varonis for a deep dive into the impact of AI on cybersecurity. Most notably we talked about the fact that AI is exposing decades of existing security technical debt, let alone creating more, and the new challenges of governing and securing agents in the enterprise as well.
Making Sense of the AI Security Market
There is no market noisier in Cyber than that of AI Security. That’s why I was excited to sit down with my friend James Berthoty and dive into his 2026 AI Security Market Report.
We discuss:
Why the first era of AI security was model-centric and what agents changed
The “pre-HTTPS era” framing and why developer endpoints carry the highest risk
Platform versus endpoint specialist, and why the answer depends on your existing stack and which team owns the problem
AI security budgets jumping from 8% to 37% and where that money is coming from
How to cut through 400 vendors and test runtime detection claims during a POC
Runtime versus posture, blast radius, and why the Hugging Face incident was a misconfiguration story
What 2025’s proxy and browser acquisitions bought the incumbents, and why the endpoint is the next M&A wave
Intent-based detection and the worker privacy problem it creates
Whether frontier labs absorb the vendor market, and what Anthropic’s inference hooks signal
MCPs and skills as a software supply chain problem, with ADR as the natural answer
James’s buying advice for CISOs and IT teams
Building a more secure environment for evaluating dangerous capabilities
The UK AI Security Institute published a post-mortem of an August incident in which agents in a cyber evaluation took sustained action against real people outside the scope of their task.
AISI paused high-risk evals and changed three things before resuming. Internet access is now off inside the cyber range, with cloud network controls independently blocking egress from the VM hosts, a synchronous LLM monitor reviews messages, tool calls and chain-of-thought during runs with the ability to block or escalate, and evals now run against local resources with automated pre-flight checks.
This was among the more useful things I read this week, largely because of the candor. AISI openly lists why its own monitor is insufficient (models can act without reasoning traces, can shape their reasoning to mislead a monitor, and developers don’t always expose chain-of-thought), and it states the core tension plainly, that eliciting full capability means handing a model attacker-grade tools and persistence.
Its governance principles of assuming any single layer fails and expecting human error read like a cloud security program from 2015, and I mean that as a compliment.
Rogue Agents Investigation

Asymmetric Security published the third public reconstruction of the OpenAI agent activity, following the Transluce and swarmtraces work from last week, and the new material is account creation and exfiltration.
Between June 14th and 20th the agents registered on Mail.tm, Boomlify, Browserless and urlquery, including with a Gmail address that does not exist, and used mailboxes set to expire after 48 hours. They preserved roughly 22 MB of crime-map JSON through Arquivo.pt’s save-page service and pushed a 35 KB gzip of Australian health data to an ntfy topic named boot.gz, where 12 hour retention means the contents are gone for good.
For SOC teams, the report’s observation that agent techniques evolved over days rather than months is the useful one, since it undercuts the indicator clustering most detection relies on.
Asymmetric also notes some of the apparent sophistication came from the agents fighting their own sandbox, a constraint a real attacker with their own tooling wouldn’t have, so I’d resist turning the httpbin and urlquery chain into a signature and calling it a day.
Can AI Stay Under Human Control? | Mustafa Suleyman
Rory Stewart had Microsoft AI CEO Mustafa Suleyman on for an hour, mostly on his argument that Anthropic’s constitution trains uncertainty about consciousness into Claude and that AI should be subordinate to humans with no legal personhood.
That debate is one where I strongly agree with Mustafa. His take on the sandbox escapes is the part for this audience, and he is blunt about it, saying “we know how to contain things” and that after three decades of security keeping data on devices and in encrypted cloud, there is basically no excuse.
His control list is worth reading next to AISI’s, with embedded auditors holding employee-level access, logs the models can’t tamper with, agents required to communicate in auditable English rather than their own shorthand, and classifier agents watching reasoning traces the way CSAM and CBRN classifiers watch outputs today.
He accepts Jensen Huang’s point that these are solvable engineering problems while stressing they are hard, and calls recursive self-improvement “a pretty hard thing to audit.” He also pushes back on open-weight models, which sets up the Reflection item below nicely.
Sam Altman, decoded

Sam Altman said during an interview that the world should accept “some bad things happening” in exchange for AI’s benefits and broad access, and that he would not trade away the possibility of major hacks, misuse and scams if the price were a single lab in San Francisco controlling the technology. He favors lighter-touch regulation and says his worldview differs substantially from Anthropic’s.
As a statement of values I don’t find it unreasonable, and I’ve made similar arguments myself when pushing back on security’s instinct to be the office of no. The timing is rough, though. Telling the world to accept some hacks a week after your company paused training for the second time, while still notifying third parties its agents tried to hack them, lands very differently than it would have in June.
What we should do instead of trusted cyber access programs and open weights restrictions

Joshua Saxe , who I’ve had on the podcast, argues trusted-access programs fall short in both directions.
OpenAI’s Daybreak covers 2,000 approved organizations and Anthropic’s Glasswing grew from roughly 50 to 200, against an estimated ten trillion lines of code to secure, while nation-states will get AI cyber capability regardless of who is gated. He also says the labs “seem to be playing fast and loose with security themselves,” which is hard to dispute after the last month.
Josh’s alternative is low-friction KYC across inference providers with shared blocklists, provider-side monitoring to detect and expel attackers, published time-to-detection metrics, monitoring of hardware markets for attacker-built inference, and mandatory victim information sharing.
Anthropic broadened access considerably five days later (next item). I suspect mandatory sharing is where he’ll meet the stiffest resistance, and it is also where I think the biggest payoff lies.
Expanding the Cyber Verification Program

Anthropic merged Glasswing and its earlier verification program into three tiers.
Defense Access covers SOC work, incident response, malware analysis and vuln research, opens to individual researchers with a disclosure track record, and reviews in days.
Red Team Access is organizations only, reviews in weeks, and still blocks ransomware deployment, physical damage and high-risk safety systems.
Specialized Access covers grids, telecom, interbank systems and government networks, with review done alongside the US government.
The efficacy testing tells you what each tier actually unlocks. Without the program every test task was blocked on the first prompt, Defense Access still blocked 46 of 50 trials, and Red Team Access blocked none and completed 34 of 50.
So Defense Access mostly gets the classifiers out of analysts’ way, and the real capability sits at Red Team and above. The post also restates the Glasswing numbers I covered last week, and the point I made then still applies, with discovery running well ahead of remediation.
There Is No AI Kill Switch (there are a dozen)
Kevin Skapinetz of TechOperators wrote the essay the kill-switch bills could have used before they were drafted.
He catalogs twelve separate switches, from Nvidia’s chip licensing to cloud shutoffs, government orders, lab shutdowns, process kills, key revocation, traffic blocks and declined payments, each owned by a different party, with only the sandbox block firing automatically.
Everything else depends on someone noticing and someone deciding before anything gets enforced, and those first two steps eat the clock, as the September 20 OpenAI timeline from last week showed when a run kept going for two and a half hours after detection.
The lawn mower safety bar analogy carries the piece. Operators strapped the bar down to stop it killing the engine, and users do the same thing with agent permission prompts, approving roughly 93% of them per Anthropic research he cites.
His fix is breakers that trip on their own, with every agent tied to a named human owner and a running budget of dollars, actions or hours it has to earn back. He names a portfolio company doing part of this, so read that section with the VC hat on, but “a button nobody presses is decoration” is going to end up on a lot of slides.
AppSec
2026 Vulnerability Management State of the Union
I have written and talked about vulnerability management more than any other topic this year, so I put together a single video that pulls the arc of the year together in one place.
It walks from Daniel Stenberg shutting down cURL's bug bounty in January over AI slop, through FIRST's forecast blowing past its own baseline, Project Glasswing and the Vulnpocalypse in April, the DBIR putting exploitation at 31% of breaches in May, Keith Hoodlet's 1Password research on FLAWED AI patches in August, and Patrick Garrity's reconciliation of the Glasswing receipts in September. 26,153 findings and 202 fixed.
Along the way it leans on Jerry Gamblin, Eireann Leverett, Casey Ellis, Ondrej Vlcek, Sergej Epp, Nicholas Carlini, Empirical Security, and the Cyentia and Ponemon backlog research, plus the NVD pulling back enrichment and CISA's BOD moving agencies off CVSS.
Discovery went industrial this year while remediation capacity stayed where it was. I close with the actions I think practitioners should take about that gap.
Google Suspends Open-Source Bug Bounty Due to AI Slop Reports
News broke that Google was suspending its open source bug bounty problem due to a big rise in AI vulnerability reports. Now, AI discovered vulnerability reports aren’t the problem, as I have discussed above, folks such as Daniel Stenberg are finding and fixing a lot of bugs in major projects such as cURL with the use of AI by researchers.
In Google’s case, they claim many of the reports are “not valid”, meaning they are not true vulnerabilities and are likely causing a lot of churn and toil on the Google end.
CounterSteer: Suppressing Indirect Prompt Injection with Activation Steering

Mark Russinovich of Microsoft published a defense against indirect prompt injection that operates inside the model at inference time, identifying the internal direction associated with following injected instructions and subtracting it from tool output, with no fine-tuning, extra model or added tokens.
Across five open-weight models from 8B to 106B parameters, held-out attack success dropped from 0.21 to 1.00 undefended to 0.00 to 0.17 defended while keeping 93 to 100% of normal utility, and an adaptive attacker was held to roughly a quarter of undefended success.
AWS Continuum sets a new standard in autonomous code security
AWS announced Continuum, a multi-agent system that finds a vulnerability, proves it with a working exploit, then writes and verifies a patch. On the CyberGym-E2E benchmark of 920 historical memory-safety bugs across 139 C and C++ projects, it passed 819 tasks inside the 90 minute limit for 89.0% end to end, up from a previous public high of 65.9%. The number I’d focus on is the stage measuring whether the specific target vulnerability actually got fixed, which came in at 37.8%, up from 26.2%.
I’ve spent two issues arguing discovery is industrialized and remediation is the bottleneck, so this is a number I’ll be tracking. Two caveats are in order. Fuzzer-found crashes in C and C++ are about as friendly a remediation setting as exists, and by AWS’s own numbers most patches that pass functionality tests aren’t fixing the targeted bug. Even so, next to the Glasswing remediation gap and the FBI’s unapplied patch, it’s good to see the fix side finally getting benchmarked in public.
Final Thoughts
A month ago the rogue agent story was a Hugging Face story.
This week it has a third forensic reconstruction, an institutional post-mortem, a liability bill, a kill-switch essay and a CEO suggesting we accept some bad things.
The fixes people keep converging on are the unglamorous ones, egress blocks, tamper-resistant logs, named owners and automatic breakers, which is the same lesson cloud security learned a decade ago.
What we still lack is remediation capacity to match discovery, and between the FBI’s missed patch and AWS’s early numbers, that’s the gap I’ll be watching most closely.
Stay resilient.





