
AI Security in Development: Agents Became Actors
The September 2026 snapshot: three risk surfaces and the defense side
Slide contents
1. AI Security in Development: Agents Became Actors
The September 2026 snapshot: three risk surfaces and the defense side
2. Five classes, one check date
153 sources checked against primary texts on September 4, 2026
3. One agent crosses three surfaces
The code the model writes; the tools it calls; the agent itself with permissions
4. A year in five numbers
44 %, five agents with CVEs, 788 packages, 28.65 M secrets, 75 of 6 202
5. The flaw share did not move: 44 %
A year ago — 45 %; the failing classes are the ones static analysis catches
6. Different methods, one picture
A third to a half of solutions carry an OWASP-class flaw
7. Prompt injection got CVE numbers
A rules file, a tracker issue, a tool description, an image, the repository config
8. Each fix is a boundary, not wording
Cursor, Copilot, Claude Code, Codex, Gemini CLI and the GitSpawn class
9. The agent as executor, not victim
Malware launches the victim's installed agent with flags that skip confirmations
10. The chain grew by two links
Packages the model invents and tools the agent installs by itself
11. Worms learned to use agents
From stealing tokens to running AI clients and squatting invented names
12. Secrets leak through the context
The provider, a tool argument, a PR, telemetry, memory, the MCP configuration
13. Two cuts against leaks
28.65 M new secrets; agent-assisted commits leak at twice the rate
14. Isolation is the last boundary
The permission ladder: from reading to writing into production
15. Human in the loop is no control
93 % approvals, 17 % classifier misses, containment breaches without malice
16. Agent identity became a category
Three MCP authorization revisions, Entra Agent ID, Okta XAA, NIST
17. Discovery is proven, fixing is not
The pipeline: find, triage, prove exploitability, fix, verify
18. 6 202 found, 75 fixed
Of 1 752 checked, 90.6 % are real; 530 handed over, 75 deployed
19. They paid for volume, not quality
Slop left with the money; the valid share returned to 15–16 %
20. Regulators caught up from four sides
Taxonomy, measurement, obligation, artifact — across the three surfaces
21. The clock is running: 24 · 72 · 14
Early warning, notification and the report on an exploited vulnerability
22. They regulate systems, not the agent
Order No. 117 from September 1, 2026, GOST R 56939-2024, Recommendations 3-MR
23. Further right is firmer, higher is riskier
Ten points from idea to standard against the size of the risk
24. Six no-regret bets
The minimum for each surface that does not depend on the next snapshot
25. What to check in the next snapshot
Six signals that will confirm or refute the forecast