Skip to content
Research Insights Made Simple logo
Live · September 15, 2026Research Insights Made Simple #30

AI Security in Development: Agents Became Actors

The September 2026 snapshot: three risk surfaces and the defense side

/ Research Insights Made Simple #30 · AI security in development

Slide contents

  1. 1. AI Security in Development: Agents Became Actors

    The September 2026 snapshot: three risk surfaces and the defense side

  2. 2. Five classes, one check date

    153 sources checked against primary texts on September 4, 2026

  3. 3. One agent crosses three surfaces

    The code the model writes; the tools it calls; the agent itself with permissions

  4. 4. A year in five numbers

    44 %, five agents with CVEs, 788 packages, 28.65 M secrets, 75 of 6 202

  5. 5. The flaw share did not move: 44 %

    A year ago — 45 %; the failing classes are the ones static analysis catches

  6. 6. Different methods, one picture

    A third to a half of solutions carry an OWASP-class flaw

  7. 7. Prompt injection got CVE numbers

    A rules file, a tracker issue, a tool description, an image, the repository config

  8. 8. Each fix is a boundary, not wording

    Cursor, Copilot, Claude Code, Codex, Gemini CLI and the GitSpawn class

  9. 9. The agent as executor, not victim

    Malware launches the victim's installed agent with flags that skip confirmations

  10. 10. The chain grew by two links

    Packages the model invents and tools the agent installs by itself

  11. 11. Worms learned to use agents

    From stealing tokens to running AI clients and squatting invented names

  12. 12. Secrets leak through the context

    The provider, a tool argument, a PR, telemetry, memory, the MCP configuration

  13. 13. Two cuts against leaks

    28.65 M new secrets; agent-assisted commits leak at twice the rate

  14. 14. Isolation is the last boundary

    The permission ladder: from reading to writing into production

  15. 15. Human in the loop is no control

    93 % approvals, 17 % classifier misses, containment breaches without malice

  16. 16. Agent identity became a category

    Three MCP authorization revisions, Entra Agent ID, Okta XAA, NIST

  17. 17. Discovery is proven, fixing is not

    The pipeline: find, triage, prove exploitability, fix, verify

  18. 18. 6 202 found, 75 fixed

    Of 1 752 checked, 90.6 % are real; 530 handed over, 75 deployed

  19. 19. They paid for volume, not quality

    Slop left with the money; the valid share returned to 15–16 %

  20. 20. Regulators caught up from four sides

    Taxonomy, measurement, obligation, artifact — across the three surfaces

  21. 21. The clock is running: 24 · 72 · 14

    Early warning, notification and the report on an exploited vulnerability

  22. 22. They regulate systems, not the agent

    Order No. 117 from September 1, 2026, GOST R 56939-2024, Recommendations 3-MR

  23. 23. Further right is firmer, higher is riskier

    Ten points from idea to standard against the size of the risk

  24. 24. Six no-regret bets

    The minimum for each surface that does not depend on the next snapshot

  25. 25. What to check in the next snapshot

    Six signals that will confirm or refute the forecast